
When I look at North Korea’s security strategy, I do not see a country relying on one weapon or one method of confrontation. I see a layered system built around nuclear deterrence, ballistic missiles, cyber operations, intelligence collection, sanctions evasion, psychological pressure, and carefully managed escalation.
This is what makes North Korea difficult to understand and even more difficult to deter. Its military strength is not measured only by the number of tanks or aircraft it possesses. Pyongyang has developed a strategy designed to compensate for its economic weakness and conventional military limitations. It uses nuclear weapons to discourage regime change, missiles to threaten regional targets, cyber operations to generate money and steal information, and diplomacy to create room for maneuver.
North Korea’s offensive strategy is therefore broader than the traditional idea of warfare. It operates across land, sea, air, space, cyberspace, and the global financial system. The country’s reach may appear limited geographically, but its activities can affect governments, banks, defense contractors, technology companies, cryptocurrency exchanges, and individuals around the world.
A strategy built on survival
North Korea’s leadership has always treated regime survival as its central national-security objective. From Pyongyang’s perspective, the fate of Saddam Hussein’s Iraq and Muammar Gaddafi’s Libya demonstrated the danger of surrendering strategic weapons or allowing outside powers to believe that a government can be removed without unacceptable cost.
I believe this historical perception explains much of North Korea’s behavior. Its nuclear program is not simply a prestige project. It is the foundation of a broader political and military strategy intended to make any attack appear too dangerous, uncertain, or costly.
At the same time, deterrence is only one part of the picture. North Korea also wants the ability to threaten South Korea, Japan, United States forces in the region, and potentially the American mainland. Its missile development supports this objective by creating different ranges and launch options.
Shorter-range systems can threaten targets on the Korean Peninsula. Intermediate-range missiles extend the threat to Japan and surrounding areas. Longer-range systems are intended to demonstrate that the United States cannot assume geographical distance will protect its territory or military assets.
This creates a complicated security environment. North Korea does not need to win a conventional war in order to achieve strategic effects. It may believe that the threat of nuclear escalation could restrict the military choices available to South Korea and the United States. In a crisis, even uncertainty about North Korea’s intentions or capabilities can produce caution.
That is the logic of coercion: the objective is not always to attack, but to convince an opponent that responding may carry unbearable consequences.
The development of nuclear capability
North Korea’s nuclear capability has developed over several decades. The program includes uranium enrichment, plutonium production, nuclear testing, warhead development, and the construction of delivery systems capable of carrying nuclear payloads.
The exact size of the arsenal is difficult to establish because North Korea does not provide transparent information and international inspectors have limited access. SIPRI estimated that, as of January 2026, North Korea had probably assembled around 60 nuclear warheads and possessed enough fissile material to potentially produce at least 90 warheads. These figures are estimates, not confirmed inventories.
The IAEA reported in March 2026 that enrichment facilities at Kangson and Yongbyon continued to operate, and that a new building at Yongbyon appeared similar to the Kangson facility. Such activity suggests that North Korea continues to expand or improve its capacity to produce fissile material.
For me, the most important issue is not simply the number of warheads. It is the direction of the program. North Korea appears to be pursuing a more diversified nuclear force, including weapons that could be delivered by different types of missiles. Diversification makes it harder for an adversary to neutralize the force in a first strike.
A nuclear arsenal supported by multiple launch systems creates what strategists call survivability. If one part of the force is destroyed, another part may remain available. North Korea has invested in road-mobile missiles, hardened facilities, submarine-related systems, and launch methods designed to complicate detection and interception.
The country has also emphasized tactical or battlefield nuclear weapons. These systems could theoretically be used against military bases, ports, airfields, command centers, or troop concentrations. Their existence creates a dangerous problem: the threshold between conventional and nuclear conflict becomes less clear.
A state may be more tempted to use a smaller nuclear weapon if it believes the purpose is limited or tactical. The opponent, however, may interpret any nuclear use as the beginning of a larger attack. This is how escalation can move beyond the intentions of both sides.
North Korea’s 2022 nuclear policy law further reinforced the importance of nuclear weapons to national defense. The law outlines circumstances in which nuclear weapons could be used, including situations involving an actual or imminent attack against the leadership, nuclear command structure, or major strategic targets. It also includes language that some analysts interpret as lowering the threshold for nuclear use.
That language matters because deterrence depends on predictability. If an adversary cannot clearly understand the conditions under which nuclear weapons might be used, it must plan for a wider range of possibilities.
Missiles and the pressure of proximity
Nuclear weapons create strategic fear, but missiles provide North Korea with visible and immediate tools of pressure. Missile launches can be used to test technology, signal displeasure, demonstrate resolve, or force the international community to focus on Pyongyang.
North Korea’s missile program serves several purposes at once. It supports nuclear delivery, strengthens conventional strike capabilities, improves military prestige, and provides political leverage.
The geography of Northeast Asia gives Pyongyang an advantage. Seoul is located close to the Demilitarized Zone, while Japan hosts important American military installations. North Korea does not need perfect accuracy to create a serious threat. A missile crisis involving major population centers or military bases could produce enormous uncertainty even if interception systems were successful in some cases.
I also see missile testing as a form of strategic communication. A launch can send multiple messages simultaneously:
- To South Korea: North Korea retains the ability to threaten national territory.
- To the United States: military pressure will carry regional consequences.
- To Japan: missile defense and security cooperation remain urgent.
- To domestic audiences: the leadership is strong and technologically capable.
- To foreign partners: North Korea remains a relevant military actor.
This communication is especially powerful because it does not always require direct combat. A missile test can change political debate, affect military exercises, influence financial markets, and shape public perceptions without crossing the line into full-scale war.
Cyber capability as an offensive instrument
North Korea’s cyber capability is one of the most effective examples of how the country uses asymmetric power. Cyber operations allow Pyongyang to reach targets that would be impossible to attack conventionally. They also offer anonymity, flexibility, and financial returns.
North Korean cyber groups have been linked to espionage, intellectual-property theft, disruption, ransomware-style activity, cryptocurrency theft, and campaigns targeting defense and technology companies. Their targets have extended across North America, Europe, Asia, the Middle East, Africa, and other regions.
According to a 2026 summary of the Multilateral Sanctions Monitoring Team report, North Korean cyber units have targeted defense companies and critical infrastructure worldwide. The report identified more than 40 countries and territories that were targeted by or involved in DPRK cyber and IT-worker activities.
This global reach is significant because North Korea’s cyber strategy is not limited to military intelligence. It also supports the country’s financial survival. Sanctions have restricted access to traditional sources of foreign currency, so cyber theft has become an important way to obtain funds.
Chainalysis reported that North Korean-linked actors stole approximately 2.02 billion dollars in cryptocurrency during 2025, contributing to a cumulative lower-bound estimate of around 6.75 billion dollars since 2016. The 2025 figure represented a major increase over the previous year.
These numbers should be treated as estimates, since attribution and valuation can change as investigations develop. Even so, the broader trend is clear: North Korean cyber operations have become more financially sophisticated and more damaging.
The threat is not limited to cryptocurrency exchanges. Attackers have reportedly targeted employees, contractors, software developers, financial institutions, technology companies, and defense-related organizations. In many cases, the initial weakness is not an advanced technical vulnerability. It may be a convincing job offer, a fake recruitment process, a malicious document, or an employee persuaded to install software.
The FBI has warned businesses about North Korean IT workers using false identities and deceptive employment arrangements to obtain access to organizations. This is an important shift in how we think about cyber threats. The attacker may not begin by breaking through a firewall. The attacker may enter through the organization’s hiring process.
The global IT-worker network
North Korea’s overseas IT-worker activity has become a significant part of its broader sanctions-evasion and cyber strategy. Workers may operate under false identities, use intermediaries, or rely on unwitting individuals to conceal their connection to the DPRK.
The purpose is often financial. Income generated through remote technology work can be redirected to the state or linked entities. But the access itself can also create opportunities for espionage, intellectual-property theft, data extortion, and further compromise.
The MSMT report identified DPRK IT workers operating in at least eight countries, including China, Russia, Laos, Cambodia, Equatorial Guinea, Guinea, Nigeria, and Tanzania. This demonstrates how globalized North Korea’s offensive network has become.
The country may be isolated politically, but its operations are not isolated technologically. Digital platforms, international payments, remote work, cloud services, cryptocurrency markets, and global supply chains give North Korean operators access to systems far beyond the Korean Peninsula.
This is why organizations need to treat identity verification and third-party risk as cybersecurity issues. A company can have strong endpoint protection and still be vulnerable if it cannot confirm who is applying for a job, who is accessing sensitive systems, or where a contractor is physically located.
Espionage and strategic intelligence
Money is only one objective. Information is equally valuable.
North Korean cyber operations have targeted defense organizations, aerospace companies, engineering firms, nuclear-related institutions, and technology businesses. Stolen information may help the country improve missile design, weapons production, military planning, or sanctions-evasion techniques.
Cyber espionage can also reduce research and development costs. A country that cannot easily purchase advanced equipment or participate openly in international supply chains may attempt to obtain technical knowledge through intelligence operations.
I do not see this as a replacement for domestic innovation. Rather, it is a force multiplier. Cyber theft can accelerate programs that would otherwise take longer and cost more.
The same logic applies to intellectual property. Industrial designs, manufacturing information, software source code, and research data can all have strategic value. In a country facing economic restrictions, stolen information can be converted into military capability or commercial advantage.
The difficulty for defenders is that espionage may remain undetected for months or years. Unlike a missile launch, which is immediately visible, cyber intrusion can operate quietly. The victim may not know what was taken until another country or organization discovers a related campaign.
Partnerships and changing strategic conditions
North Korea’s international position has also changed. Its relationships with China and Russia remain important, while military cooperation with Russia has attracted increased attention. The war in Ukraine and shifting geopolitical competition have created new opportunities for Pyongyang to trade military support, labor, weapons, or political alignment for economic and technological benefits.
I would be cautious about assuming that every reported partnership gives North Korea unlimited access to advanced technology. International relationships are complicated, and states cooperate in some areas while competing or withholding in others. However, diplomatic isolation is no longer as complete as it once appeared.
This matters because North Korea’s offensive capabilities develop within a wider strategic environment. Access to foreign components, expertise, financial networks, and diplomatic cover can reduce the pressure created by sanctions.
At the same time, the country’s cyber capability can support international partners indirectly by providing intelligence, illicit revenue, or disruptive options. The result is a security environment in which cyber, nuclear, missile, and geopolitical developments cannot be examined separately.
What makes North Korea dangerous
North Korea is dangerous not because it possesses overwhelming conventional power. Its danger comes from the combination of capabilities and the uncertainty surrounding its decision-making.
A conventional military crisis could involve artillery, missiles, cyberattacks, special operations, and nuclear signaling at the same time. A cyberattack could be used to disrupt communications before a missile launch. A missile test could coincide with disinformation campaigns. Financial theft could continue during diplomatic negotiations.
This combination complicates the response. If a government reacts too weakly, Pyongyang may believe pressure works. If it reacts too strongly, North Korea may interpret the response as preparation for regime change.
There is also the problem of miscalculation. North Korean leaders may use aggressive rhetoric to strengthen bargaining power without intending immediate war. Foreign governments, however, must prepare for the possibility that rhetoric reflects genuine military planning.
The danger is therefore not only deliberate aggression. It is the possibility that signals are misunderstood, cyber incidents are misattributed, or military exercises are interpreted as preparation for attack.
The challenge for policymakers and businesses
For governments, the response requires more than missile defense. It requires coordinated intelligence, sanctions enforcement, cyber resilience, financial monitoring, and diplomatic communication.
For businesses, North Korea’s activities demonstrate that national security threats can enter through ordinary corporate processes. Organizations should pay attention to:
- Identity verification for remote workers and contractors.
- Unusual access from foreign locations or unfamiliar devices.
- Requests to install software or move communications outside approved platforms.
- Cryptocurrency custody and transaction controls.
- Software supply-chain risks.
- Sensitive data leaving the organization in small, unnoticed transfers.
- Recruitment fraud and fake technical assignments.
- Third-party vendors with unclear ownership or location.
These measures are not directed only at North Korea. They are part of basic security hygiene in a world where state-backed groups increasingly use criminal methods.
North Korea’s Evolving Threat Landscape
I expect North Korea to continue developing its nuclear arsenal, missile technologies, cyber operations, and overseas financial networks. The country has strong incentives to do so. These capabilities provide security, money, influence, and bargaining power.
The central question is whether external pressure can change the cost-benefit calculation in Pyongyang. Sanctions alone have not stopped the nuclear or cyber programs. Military pressure alone risks escalation. Diplomacy without verification may create temporary pauses without resolving the underlying problem.
A realistic policy must acknowledge that North Korea is unlikely to abandon its nuclear weapons quickly. The immediate objective may therefore be risk reduction: preventing accidental conflict, strengthening communication channels, limiting proliferation, protecting financial systems, and making cyber operations less profitable.
The global community must also recognize that North Korea’s offensive strategy is no longer confined to East Asia. Its missiles remain primarily a regional military threat, but its cyber and financial operations are global. A company in Europe, a cryptocurrency exchange in Asia, a defense contractor in North America, or a technology worker in Africa may all become part of the same strategic picture.
That is the most important lesson I take from North Korea’s rise as a multidimensional security actor. Geography still matters, but cyberspace has weakened its boundaries. Nuclear weapons create fear, missiles create pressure, and cyber operations create reach.
North Korea’s power lies in the way these tools reinforce one another. The country may not be a traditional global power, but it has built a strategy capable of producing global consequences. Understanding that strategy is the first step toward reducing the risks it creates.




