Summary

  • LACNIC records connect Bevil Wooding to Internet exchange establishment in Grenada, the British Virgin Islands, Dominica, and Barbados, as well as to the founding and program work of the Caribbean Network Operators Group.
  • An Internet Society field report authored by Wooding and an ICANN root DNSSEC update add separate continuity layers: regional recovery planning and a distributed recovery-key role, neither of which should be confused with sole control or proof of later outcomes.

An operational record rather than a general biography

People who work on Internet infrastructure are often described with broad labels: pioneer, strategist, community leader, or expert. Those terms may be accurate in ordinary conversation, but they are weak foundations for a technical profile. An operational article needs to identify the constraint, the person's documented role, the decisions or practices visible in the public record, and the boundary beyond which attribution would become speculation.

Bevil Wooding's record supports that narrower approach. LACNIC's 2013 Lifetime Achievement Award record identifies him as Packet Clearing House's Caribbean Outreach Manager and links him to the establishment of Internet exchange points in Grenada, the British Virgin Islands, Dominica, and Barbados. The same record identifies him as a founding member and program director of the Caribbean Network Operators Group, commonly known as CaribNOG.

A later LACNIC report on a CaribNOG partnership identifies Wooding as a CaribNOG founder and records his description of the group as a place where Caribbean operators could identify regional network problems, share knowledge, and work with partners. That is a person-level record tied to an operating community, not merely an event appearance.

The Internet Society's post-hurricane Caribbean field report adds another layer. It includes an OECS section titled "From Crisis to Resilience: Strengthening Critical Caribbean Internet Infrastructure," authored by Wooding in his role as Special Advisor for Strategic ICT to the OECS Commission. The section discusses the exposure of communications networks during the 2017 hurricane season and describes proposed work by CaribNOG and a regional resilience commission.

Finally, an ICANN root DNSSEC update lists Wooding among the recovery key shareholders in the trusted community representative model. That record concerns a bounded recovery function in a distributed trust system. It does not make any individual the controller of the DNS root.

Together, these sources support an article about operating continuity. They do not support a complete life story, a claim of sole authorship, or a claim that every proposal was implemented.

Four layers of continuity

The records place Wooding at four different layers of Internet continuity.

The first layer is local interconnection. An Internet exchange point gives networks a place to exchange traffic under shared technical and operational rules. Establishing one requires more than installing a switch. Participants need a neutral operating model, a peering LAN, member procedures, route-policy expectations, monitoring, maintenance ownership, and a way to resolve incidents.

The second layer is operator knowledge. A network operator group can make practices portable across organizations. It can give engineers a place to compare routing behavior, rehearse configuration changes, discuss failures, and establish contacts before an emergency. The group is not a regulator and does not make its members' production decisions. Its practical value comes from repeated technical work.

The third layer is recovery planning. A severe storm can damage power, backhaul, towers, buildings, access networks, and staff mobility at the same time. Restoring Internet service therefore requires coordination among operators, utilities, governments, regional bodies, vendors, and outside assistance. A report can identify constraints and propose actions, but the running network remains the final test.

The fourth layer is distributed trust. DNSSEC at the root uses cryptographic processes, secure facilities, documented ceremonies, and multiple trusted representatives. Recovery material is deliberately divided so that one person or organization cannot reconstruct it alone. Continuity depends on the process, records, equipment, and participants remaining usable under exceptional conditions.

These layers should not be collapsed into one story of personal influence. They involve different systems, organizations, time periods, and decision rights. Wooding's record is useful precisely because it provides dated links to each layer while leaving room for the other operators and institutions that made the work real.

Internet exchange points are operating systems

An IXP is sometimes explained as a local place where networks exchange traffic. That is correct, but incomplete. The exchange is also an operating system in the organizational sense. It has identities, interfaces, expected behavior, maintenance procedures, incident contacts, and rules for changing shared infrastructure.

LACNIC's award record attributes to Wooding a part in establishing IXPs in four Caribbean jurisdictions. The wording matters. "His part" supports participation; it does not specify that he designed every topology, negotiated every agreement, installed every device, or operated every exchange after launch. Local network operators, host institutions, regulators, technical partners, and exchange staff would have held their own responsibilities.

The operational significance of the record is not diminished by that boundary. Starting an exchange requires participants to solve a coordination problem that no single router can solve. Each member controls its own autonomous system and routing policy. The shared exchange must still provide a predictable environment in which those independent networks can meet.

A durable IXP needs several forms of evidence:

  • a current participant and port inventory;
  • clear ownership of the switching platform and facilities;
  • an addressing and peering-LAN plan;
  • documented bilateral or route-server options;
  • route-policy and maximum-prefix expectations;
  • monitoring of ports, sessions, traffic, and reachability;
  • maintenance, escalation, and rollback procedures;
  • records that can be updated when members or equipment change.

None of those records is a substitute for the live exchange. A participant list can be current while a session is down. A route-server configuration can be valid while a member announces an unexpected prefix. A traffic graph can show packets without explaining whether the path matches the intended relationship.

The reverse is also true. A working session does not eliminate the need for records. Operators need to know which network is connected, who owns the change, what prefixes are expected, and how to coordinate when observed behavior departs from policy. The exchange survives staff changes and incidents only when those facts remain recoverable.

Wooding's IXP record therefore points to a form of continuity built from shared operations. It is not a claim that an exchange belongs to one person.

Why local interconnection matters during disruption

The resilience value of an IXP depends on the actual topology. If two local networks can exchange traffic locally, some communication may avoid an international path. That can reduce dependence on a distant transit route for the traffic that is eligible to remain local. It may also give operators a shared point at which to observe routing and coordinate during an incident.

Those benefits are conditional. An exchange does not create electricity, repair access networks, restore a failed data center, or guarantee that local services remain available. A physically local switch may still depend on vulnerable power, cooling, transport, or facilities. Members may continue to use international paths for policy or engineering reasons. A local route may exist while the service it reaches is unavailable.

The safe operational question is not, "Does this country have an IXP?" It is, "Which communications can still work when a specific dependency fails?"

Answering that question requires a dependency map. Operators need to identify the exchange facility, power sources, backup duration, upstream links, member access circuits, route servers, DNS services, monitoring, staff access, and the local services that users may need during disruption. Each dependency should have an owner and a verification method.

The map then has to be tested. A tabletop exercise can reveal missing contacts, but it cannot prove that routes converge or generators carry the intended load. A routing test can prove path behavior, but it cannot show whether staff can reach a damaged facility. A service probe can reveal availability, but it cannot explain who has authority to make an emergency change.

This layered method matches the limits of Wooding's public record. LACNIC establishes his participation in IXP development. The Internet Society report establishes his authorship of a regional resilience analysis. Neither source measures the performance of the four named exchanges during every storm. The article should connect the two records as operational surfaces, not convert them into an unsupported outcome claim.

CaribNOG as a continuity mechanism

CaribNOG adds a human and procedural layer to the infrastructure story. LACNIC describes it as a community of network operators and other stakeholders that shares technical experience and develops skills. Its 2015 report quotes Wooding on the premise that Caribbean practitioners are well placed to identify regional network problems while still benefiting from partnership and collaboration.

That model can contribute to continuity in three ways.

First, it creates repeated contact among people who may need to coordinate later. During a routing leak, facility failure, cable disruption, or severe storm, the time required to identify the right operator can become part of the outage. An operator community cannot replace formal escalation paths, but it can reduce the distance between organizations.

Second, it provides a place to turn isolated experience into a reusable method. A presentation about a failure is useful only if participants can distinguish what was observed, what was inferred, what change was made, and what evidence showed recovery. Good operator training makes that sequence explicit.

Third, it can expose differences among networks before those differences become emergency surprises. Small and large providers may use different equipment, staffing models, upstream arrangements, and monitoring. A shared technical exercise can reveal where a procedure assumes tools or capacity that another operator does not have.

Community language should still be handled carefully. A network operator group does not automatically represent every operator or user. Consensus in a room does not prove that a practice is technically correct. Participation does not establish implementation. An agenda does not prove a production result.

The LACNIC daily recap helps define this boundary. It names Wooding among speakers at a CaribNOG meeting and says the gathering focused on technical experience and capacity. It separately identifies Stephen Lee as the presenter of the Caribbean IXP journey. That separation is valuable: the event belongs to a group of contributors, and the public record should preserve who did what.

Wooding's role can therefore be described as documented participation in building and programming an operator community. The later operating decisions remained with the networks and people responsible for them.

From crisis to resilience

The 2018 Internet Society report gives the continuity discussion a concrete failure context. Its introduction describes the loss of telecommunications and Internet connectivity after the 2017 Caribbean hurricane season. Wooding's OECS section places that disruption within the constraints of small states and calls attention to the vulnerability of regional communications infrastructure.

The report says CaribNOG was developing software applications related to disaster preparedness and response and designing technical workshops for network operators and engineers. It also describes a Caribbean Telecommunications Union commission intended to examine communications vulnerabilities and produce recommendations for governments, regulators, and ministries.

These are documented plans and institutional commitments at the time of publication. They should not be rewritten as completed deployments. The report itself distinguishes the need for fact gathering, recommendations, and later action. Responsible reporting preserves that sequence.

The operational lesson is broader than any one storm. Recovery starts with an inventory of what failed and why. A headline such as "connectivity was lost" hides several possible causes:

  • commercial power may have failed;
  • backup generation may have run out of fuel;
  • towers, poles, or antennas may have been damaged;
  • terrestrial or submarine links may have failed;
  • a facility may have remained intact but inaccessible;
  • local routing may have survived while upstream reachability failed;
  • DNS or hosting dependencies may have been located outside the reachable region;
  • staff and suppliers may have been unable to travel.

Each cause implies a different control. More redundant routers do not solve a fuel problem. A second upstream does not help if both paths share a damaged landing station. A resilient data center does not preserve access for users whose last-mile networks are down. An emergency contact list does not help if it is stored only in an unreachable cloud service.

A resilience program therefore needs failure-specific evidence. It should record dependency, owner, expected duration, test method, observed result, exception, and repair action. The report authored by Wooding contributes an assessment and a call for coordinated work. Production systems and later tests would be needed to establish the result.

Resilience is a sequence of verifiable decisions

The phrase "resilient network" can become advocacy copy if it is not connected to testable conditions. A more useful approach is to define a sequence of decisions.

The first decision is scope. Which services must remain available, to whom, and for how long? Emergency voice, messaging, authoritative DNS, local government information, banking, health services, and ordinary Internet access may have different requirements and dependencies.

The second decision is failure model. Which events are included: loss of commercial power, failure of one facility, loss of one submarine path, equipment damage, staff unavailability, or a region-wide event? A design cannot be evaluated without a stated failure.

The third decision is topology. Which physical and logical paths carry the service? This includes access, backhaul, exchange, transit, hosting, DNS, authentication, and monitoring. The map should distinguish shared dependencies that make two apparent paths fail together.

The fourth decision is operational authority. Who can change routing, replace equipment, authorize emergency access, obtain fuel, contact a peer, or restore a service? A technical option that no available person can execute is not a recovery plan.

The fifth decision is evidence. What observation will show that the service remains usable? Device status is not enough. Operators need external route visibility, DNS resolution, application probes, and user-path tests appropriate to the service.

The sixth decision is rollback. An emergency change can create a second failure. Operators need a condition for reversing it and a record of what changed.

This framework is an analytical reading of the continuity problem, not a claim that Wooding's report prescribed every item. The report supplies the documented failure context, the emphasis on stronger infrastructure, and the proposed coordination mechanisms. The framework translates those concerns into questions that a network can answer with current evidence.

Physical recovery and routing recovery are different

Connectivity is created by both physical and logical systems. A link can be physically restored while routing remains wrong. A BGP session can be established while the underlying path is unstable. A route can be visible while the destination service lacks power.

Operators should therefore maintain separate recovery states.

Physical state includes power, cooling, building access, cable integrity, equipment condition, and spare availability. Link state includes optical levels, interface errors, carrier handoff, and capacity. Routing state includes sessions, accepted prefixes, selected paths, announcements, route validity, and convergence. Service state includes DNS, application response, authentication, and user reachability.

The states must be correlated by time. If a service returns after a routing change, that does not prove the routing change caused recovery unless the dependency chain supports that conclusion. If an interface remains up during packet loss, the link state is incomplete. If a route collector sees a prefix, users on another path may still fail.

An IXP can provide useful local observations, but it is one point in the chain. A network operator group can help peers compare evidence, but it does not own every device. A regional commission can recommend controls, but operators and authorities must implement and test them.

This separation protects the person-level story from exaggeration. Wooding's records connect him to interconnection work and resilience analysis. They do not show that he personally restored a specific link, configured a specific router, or caused a measured recovery. The contribution documented here is coordination and operational framing across several layers.

DNS continuity is not only a routing problem

Users often experience Internet services through names. A route to a server may exist while DNS resolution fails. A resolver may operate while the authoritative chain is unreachable. Cached data may keep some names working until time-to-live values expire, creating a delayed failure that is easy to misread.

DNS continuity therefore needs its own dependency and evidence model. Operators should identify authoritative servers, resolver infrastructure, parent-zone relationships, DNSSEC validation, key-management responsibilities, network paths, power, and monitoring from outside the local failure domain.

The ICANN DNSSEC update that lists Wooding as a recovery key shareholder concerns the root's trust infrastructure, not the operation of a Caribbean resolver or country-code domain. The connection is conceptual and operational: both systems depend on distributed responsibilities, accurate records, tested recovery procedures, and the ability to act under exceptional conditions.

The root DNSSEC model deliberately divides roles. ICANN's public material describes crypto officers and recovery key shareholders as trusted community representatives who participate in defined parts of key management and recovery. The system is designed so that a threshold of people and controlled materials is required. That arrangement reduces dependence on one person.

It also creates operational obligations. The identities and status of representatives must remain current. Physical material must remain protected and recoverable. Ceremonies and facilities need records that independent observers can inspect. Replacement and succession procedures must work before an emergency.

Wooding's listing is evidence of one bounded role in that design. It should not be described as ownership of a key, control of DNSSEC, or authority over the root zone. The value of the role comes from participating in a distributed process whose controls are stronger than any individual.

Distributed trust requires precise language

Security roles are especially vulnerable to inflated language. A phrase such as "held the key to the Internet" would be inaccurate and misleading. Root DNSSEC does not depend on a single ordinary key in the custody of one person, and a recovery key shareholder cannot act alone to control the root.

The ICANN update explains the recovery role at a high level. Recovery key shareholders hold smartcards containing portions of material used in a recovery process. A threshold arrangement is intended for an exceptional scenario involving loss of normal key-management facilities. The design distributes capability and limits unilateral action.

Three distinctions should remain visible.

First, custody is not sovereignty. Holding a component within a controlled recovery process does not grant policy authority over the DNS namespace.

Second, recovery capability is not routine operation. A role intended for exceptional restoration should not be described as day-to-day management.

Third, identity records are not the control itself. A list of representatives tells the public who was assigned a role at a point in time. The security result depends on the procedures, secure equipment, threshold design, audits, facilities, and actual conduct of ceremonies.

This is the same reason an IXP participant list cannot prove session health. Records establish identity and expected relationships. Running systems and observed procedures establish current reality. Both are necessary, but neither should impersonate the other.

Wooding's public DNSSEC record is meaningful because it shows that his infrastructure work extended into a system built around distributed continuity. The safest description remains the narrow one: ICANN listed him among recovery key shareholders in the trusted community representative model.

Records as ledgers, not substitutes for operation

The sources used in this profile are records. They identify roles, events, publications, and institutional plans. Their value depends on readers using them for the questions they can answer.

LACNIC's award page can answer whether the institution publicly attributed IXP and CaribNOG work to Wooding. It cannot answer whether a given exchange is currently operational.

The CaribNOG report can answer how Wooding described the group's purpose and how LACNIC characterized the event. It cannot answer whether every member adopted a practice.

The Internet Society report can answer what Wooding wrote about the 2017 disruption and what initiatives were described at publication time. It cannot answer whether all recommendations were later completed.

The ICANN update can answer whether Wooding appeared in the published list of recovery key shareholders. It cannot answer whether he currently holds the role or whether a recovery action has ever been required.

This disciplined use of records is not a limitation to work around. It is the basis of reliable infrastructure reporting.

A registry, participant list, or role record is a ledger. It helps preserve identity, responsibility, and change history. Running networks, current ceremonies, routing observations, and service probes show operational reality. When the two diverge, the divergence is a signal for investigation, not permission to choose whichever version supports a preferred story.

Continuity improves when records have owners, timestamps, update procedures, and links to observable systems. It weakens when a historic title is repeated as a present role, when a planned action is rewritten as a result, or when an institution's achievement is collapsed into one person's biography.

Decision ownership must stay distributed

The Internet's operation is distributed not only in topology but also in authority. Different organizations own different decisions.

An IXP operator owns the shared platform and its operating procedures. Member networks own their routing policies and connections. Facility providers own power and physical access under their agreements. Resource registries maintain number-resource records within their mandates. DNS operators manage zones and resolvers. ICANN's key-management process assigns bounded responsibilities to multiple participants. Governments and regulators may have emergency or sector roles, but they do not replace network operations.

CaribNOG can connect these people and help them learn from one another. It cannot make a production change on behalf of every member. A regional commission can produce recommendations. It cannot prove that each operator implemented them. An adviser can frame a problem. Local teams still own the work and evidence.

This distribution is a strength when responsibilities are explicit. It becomes a risk when everyone assumes another party owns a dependency.

A continuity plan should therefore identify:

  • the organization that owns each asset or decision;
  • the named operational role, with a maintained succession path;
  • the evidence required before a change;
  • the observation required after a change;
  • the escalation path when shared infrastructure is involved;
  • the boundary beyond which a different authority must act.

Wooding's record can be read as participation at several of these handoffs. He is connected to exchange establishment, operator-community programming, regional resilience analysis, and a limited DNSSEC recovery role. The handoffs do not make him the owner of every layer. They show why continuity work often occurs between organizations rather than inside one job description.

Small-state constraints change the recovery equation

Wooding's Internet Society report emphasizes the vulnerability of small Caribbean states. The operational implications deserve careful treatment.

A smaller market may have fewer facilities, suppliers, specialized engineers, international paths, and spare systems. A severe event can affect a large share of national infrastructure at once. Travel between islands may be disrupted. Replacement equipment may have to cross borders. Power restoration and telecommunications restoration may depend on one another.

At the same time, small scale can make some coordination more direct. Operators may know one another through regional forums. A local exchange can keep eligible traffic within the region. A bounded service set may be easier to map. A technical exercise can include a large share of relevant organizations.

Neither condition guarantees resilience. Scarcity can concentrate failure. Familiarity can leave procedures undocumented. A local exchange can itself become a shared dependency. External assistance can be delayed by unclear authority or incompatible equipment.

The useful response is to make constraints explicit. An operator should know how long backup power lasts under measured load, which links share a landing point, where spare optics are stored, which services depend on external DNS or hosting, which staff can reach a site, and which organization can authorize emergency access.

Regional coordination can then focus on concrete gaps. A training session can test route restoration. A shared inventory can identify compatible spares without exposing private data. An exercise can test whether contacts and authority remain usable when ordinary communications fail. A post-event review can separate physical damage, procedural delay, configuration error, and dependency failure.

The report authored by Wooding supports the urgency and regional setting for this analysis. Current operator evidence would be needed to evaluate any specific network today.

What the public record does not establish

The sources do not establish a complete chronology of Wooding's career. They identify particular roles and contributions at particular times.

They do not establish sole authorship of any IXP. LACNIC attributes a part in establishment, and local participants necessarily held their own roles.

They do not establish that every IXP named in the award record remains active, has a particular traffic level, or performed in a particular way during the 2017 hurricanes.

They do not establish that every CaribNOG participant implemented the methods discussed at meetings or workshops.

They do not establish that software or workshops described in the 2018 field report were completed exactly as proposed. The report records work and plans at publication time.

They do not establish that Wooding personally restored a network after a hurricane, configured a production router, managed a power system, or directed every regional recovery decision.

They do not establish present ownership, employment, or current organizational titles. Historical role descriptions should remain tied to their source dates.

They do not establish that he controlled the DNS root, held a complete root key, designed DNSSEC, or could perform recovery alone. ICANN's model is distributed by design.

They do not establish private security procedures, credentials, locations, or ceremony details beyond the public material. None are needed for this profile.

They do not establish customer counts, traffic volumes, uptime gains, cost savings, or economic outcomes.

These exclusions keep the article useful. They prevent a real operational record from becoming a heroic narrative. They also protect institutions and collaborators from being erased by an overly broad claim about one person.

A practical continuity framework

The four public records can be translated into a practical framework without claiming that Wooding authored the framework itself.

Interconnection: identify which networks can exchange traffic locally, how sessions are established, which policies apply, and which shared dependencies could fail together.

Operator coordination: maintain current escalation roles, exercise technical procedures, preserve lessons as runbooks, and distinguish discussion from production adoption.

Physical recovery: map power, facilities, access, backhaul, spares, suppliers, and staff availability. Test the time assumptions rather than relying on nominal redundancy.

Routing recovery: record expected sessions, prefixes, paths, and validation state. Observe the network from more than one point and preserve rollback criteria.

Service recovery: test DNS, applications, authentication, and user paths. Device health alone is insufficient.

Distributed trust: preserve role records, threshold procedures, secure material, audits, succession, and exceptional recovery tests without concentrating capability in one person.

Evidence discipline: timestamp every observation, identify the owner, separate a plan from a result, and state what remains unknown.

This framework treats continuity as correspondence among records, authority, and running systems. It does not place a community, registry, regulator, or individual above the network. Each layer contributes evidence for a different question.

Wooding's public record provides person-level examples at the points where those layers meet. LACNIC links him to IXP and operator-group work. Internet Society published his regional resilience assessment. ICANN listed him in a distributed DNSSEC recovery role. The record becomes stronger when each fact remains in its proper scope.

Conclusion

Bevil Wooding's documented contribution to Caribbean Internet infrastructure is not best understood as a general story of technology leadership. It is a record of work at operational handoffs.

LACNIC links him to the establishment of IXPs in four Caribbean jurisdictions and to the creation and programming of CaribNOG. Those activities concern shared interconnection and the transfer of practical knowledge among operators.

The Internet Society field report links him to a post-hurricane assessment of critical regional infrastructure. It describes the scale of the continuity problem and proposed work by operator and regional bodies, while leaving implementation and measured results to later evidence.

ICANN's DNSSEC update places him in a bounded recovery role within a distributed trust model. The role matters because no individual is meant to control the process alone.

Across all four layers, the same discipline applies. Records should identify responsibility without pretending to operate the system. Plans should be distinguished from results. Institutions and collaborators should retain credit for their decisions. Running infrastructure should be observed under a stated failure model.

That is the reality behind resilience. It is not a slogan and not the property of one person. It is the repeated work of keeping interconnection, people, physical systems, trust processes, and evidence usable when normal assumptions fail.

Wooding's public record is significant because it shows sustained participation in that work across distinct systems. The strongest account is also the most bounded: a person connected to Caribbean exchange development, operator coordination, resilience analysis, and distributed DNS recovery, with each contribution documented at the level the sources can support.

Sources