DNSSEC uses cryptographic algorithms to sign DNS data, and like all cryptographic systems, these algorithms may eventually become vulnerable to cryptanalysis or brute-force attacks.
A scheduled key rollover reduces the amount of time a key remains in use, limiting the opportunity for an attacker to compromise it. By periodically replacing keys, DNSSEC operators reduce the risk associated with long-term key exposure and help maintain the security of the DNSSEC-signed zone.