Nuclear Missiles Are Not N.Korea’s Only Threat

North Korea has launched 22 missiles in 15 tests in 2017. According to US intelligence sources, the most recent test detonated a 140-kiloton nuclear device, which the North Koreans claim was a hydrogen bomb.

That’s 10 times as powerful as the atomic bomb the United States dropped on Hiroshima in World War II. The UN secretary-general has continuously condemned North Korea’s ballistic missile launches as serious violations of UN Security Council resolutions.

Meanwhile, President Donald Trump has promised new sanctions against North Korea that will allow the United States to target businesses, individuals and financial institutions that aid North Korea’s regime, and the Chinese central bank has begun to implement strict UN sanctions against Pyongyang.

The missile tests are posturing by Kim Jong Un and a clear attempt to show dominance to the United States and its allies. They are likely part of a strategy that follows Iran’s playbook: Get close to developing a nuclear weapon and the rest of the world will make a deal.

But they are also a major distraction from a much bigger issue. The true risk when it comes to North Korea is its cyberattack capabilities.

North Korea has invested heavily in cyberattack operations to disrupt its Western enemies. Western Intelligence services blamed the 2014 attack against Sony on North Korea’s spy agency, the Reconnaissance General Bureau.

North Korea is also believed to be responsible for the cyber heist at Bangladesh’s central bank and the global WannaCry ransomware attack from earlier this year.

Pyongyang’s cyber-spies conduct low-cost, high-impact, deniable attacks around the world to harm enemies, disrupt the West and steal money. Financial institutions are particularly at risk of theft as North Korea bleeds funds to support its nuclear program.

The goal for North Korea’s cyberattack operations, beyond flying under the radar, is to inflict death by a thousand cuts, a deliberate and organised disrupt-and-attack approach in line with the country’s national strategy. Arguably, the more money and resources North Korea can steal via cyberattacks, the stronger its kinetic military can become.

Despite severe unemployment rates and terrible living conditions for its masses, North Korea invests in, and educates, a portion of its population in science and technology to work for its cyber military agency, which is a top-level job in the country.

Security experts and North Korean defectors have placed the numbers in North Korea’s cyber army in the thousands. Students are often handpicked to join the elite corps.

While all citizens must serve for a period of time in the military, those who serve as cyber-spies continue to work in a surge capacity when the authoritarian government requires their support. In that respect, North Korea has at its disposal a dedicated and systematically developed cyber army on call.

North Korea’s most frequent target of cyberattacks is its southern neighbor.

As pressure from the West to derail North Korea’s nuclear weapons program increases, Kim will likely continue to develop cyberattack capabilities in response. In turn, the United States should develop contingency plans to respond to a direct cyberattack from North Korea.

Most critically, we should develop an escalation policy that establishes when a cyberattack will be considered an act of war. Cyberattacks can affect more than just bank accounts or identity theft; they can shut down power transmission, turn off water and prevent aircraft control towers from safely landing planes.

The United States needs to invest heavily in cybersecurity for critical infrastructure, hardening key control elements across the country and doubling down on protections to our financial systems and power grids.

In North Korea and elsewhere, the battleground for future conflicts will be found in both kinetic and cyberwar theaters.

As we all continue to pay attention to Kim’s nuclear missile posturing, it’s important we not lose sight of North Korea’s cyberattack initiatives, which have successfully disrupted the West in recent years and will continue to do so in the future if we don’t take action.

CarbonBlack:

You Might Also Read: 

N.Korea's Cyber Threats To S.Korea

How Worried Should We Be About a Nuclear War With North Korea?:

 

 

« Multicloud - The Next Step In Cloud Computing
Poor Coding Limits IS Hackers »

ManageEngine
CyberSecurity Jobsite
Check Point

Directory of Suppliers

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

NordLayer

NordLayer

NordLayer is an adaptive network access security solution for modern businesses — from the world’s most trusted cybersecurity brand, Nord Security. 

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

Wall Street Technology Association (WSTA)

Wall Street Technology Association (WSTA)

The Wall Street Technology Association (WSTA) provides financial industry technology professionals with forums to learn from and connect with each other.

Redcentric

Redcentric

Redcentric is a leading UK IT managed services provider. We deliver managed IT, cloud computing, data backup, information security services and managed networks.

Apcon

Apcon

Apcon's mission is to provide valuable network insights that enable security and network professionals to monitor, secure and protect their data in both physical and virtual environments.

Onapsis

Onapsis

Onapsis is a pioneer in cybersecurity and compliance solutions for cloud and on-premise ERP and business-critical applications.

I-Tracing

I-Tracing

I-TRACING are experts in IT security, specialized in legal compliance of information systems, security of information systems, and the collection of digital evidence and traces.

NAVEX Global

NAVEX Global

NAVEX Global’s compliance management system consolidates your entire GRC program onto a scalable cloud-based platform.

Communications Authority of Kenya

Communications Authority of Kenya

The Authority is responsible for facilitating the development of the information and communications sectors including; broadcasting, telecommunications, electronic commerce and cybersecurity.

SAST

SAST

SAST provide Static Application Security Testing as a service based on SAST Tools.

Berkeley Varitronic Systems (BVS)

Berkeley Varitronic Systems (BVS)

Berkeley Varitronics Systems is an engineering think tank delivering custom wireless RF engineering products and solutions including cyber security.

Quantinuum

Quantinuum

Quantinuum is the combination of Cambridge Quantum with Honeywell Quantum Solutions, structured to drive the future of quantum computing.

Nukke

Nukke

Nukke offers advanced cybersecurity software and tailored solutions for your business.

TraitWare

TraitWare

The TraitWare mission is to increase user and company security while simplifying access to digital and physical resources through the elimination of the need for usernames and passwords.

Hubble

Hubble

Hubble grew from the idea that legacy solutions were failing to provide organizations with the asset visibility they needed to effectively secure and operate their businesses.

Symbiotic Security

Symbiotic Security

Symbiotic Security revolutionizes code security by integrating an AI-driven security coach directly within developers' IDEs.

GlitchSecure

GlitchSecure

GlitchSecure helps companies secure their products and infrastructure through real-time continuous security testing.

CyberHeed

CyberHeed

CyberHeed is the first compliance automation platform purpose-built around Agentic AI - transforming cybersecurity compliance with automation and intelligence.