Somebody Finally Threw the First Punch

Iran went after three dozen Minnesota water systems. Minnesota makes ammunition. Nobody should have to draw you a map, but I’m going to draw you a map.

When I was initially reading the reporting on this story, it felt darkly comedic. It felt like a Coen Brothers film. The mayor of a little town called Branham, Minnesota, had an experience where he found out a plant operator had a water tower that was calling for water, but the well wasn’t operating. I can see this playing out in my head as the opening scene before things get tragic. The mayor is this guy named Nate George. He’s a retired Air Force Master Sergeant. He did 20 years of service, and by all accounts, he seems like a good, hard-working, salt-of-the-earth kind of guy. He’s this perfect archetype for the mayor of a Midwestern town with about 2,000 people.

I think it would be a good opening plot device for a movie. An IRGC-affiliated cybersecurity crew reaches across an ocean and puts their hand on a valve in a town even most Minnesotans couldn’t find on a map. The only reason anyone noticed is because a plant operator saw something on an internal dashboard that just didn’t make sense. He looked at the situation and thought, “Huh, that doesn’t look right.” Then he called the mayor, who just happens to be in his fantasy football league. This only works because it’s a small town.

That’s our early warning system against the IRGC. A guy named Dave has a feeling in his gut that something doesn’t quite add up about the water tower, so he calls the mayor of the town, a dude named Nate, who is in his fantasy football league.

Look, I’m glad we caught it, but we can’t rely upon fantasy football relationships to be our warning system. As a side note, I hope that league decides to give Dave the first pick in this year’s draft as a thank you to his nation.

Me, screaming “I told you so,” but in a way that is subtle… but not really.

Back in November I wrote a piece called The Arsenal of Democracy Has a Glass Jaw. The argument was simple enough that it didn’t require you, the reader, to be any kind of cybersecurity genius: The United States has the most formidable defense industrial base in human history, and it is bolted directly onto a foundation of loose sand. The sand is city, county, and special-district infrastructure. Water. Power. Wastewater. The stuff that no defense contractor owns, no combatant command defends, and no line item in the NDAA covers.

I want to make something abundantly clear: I’m not trying to score points for any of this. I don’t think anybody else is trying to score points on this either. Every OT security dude or dude-ette has been screaming about this since the Oldsmar incident in 2021. If you see your mouse moving on your screen and you’re not the one moving it, it’s bad. If your mouse is changing the chemical treatment of the water for a local municipality and you’re not the one controlling your mouse, that’s really bad. That’s Oldmar, just to catch you up.

If you go to any water conference, any electricity conference, any telecom conference, in any hotel where they have those giant halls, where people sit on stage in cheap office chairs, they’ll tell you the same thing. We’ve all been saying the same thing for at least a decade. I’m not holding some crazy contrarian opinion here. It’s like me predicting that the Dallas Cowboys are going to have an emotionally devastating way to find a new way to lose in January. Everyone knows the Dallas Cowboys are going to be an emotionally devastating team that doesn’t win the Super Bowl. This is not news.

This is not a victory lap. I’m not patting myself on the back. This is more like CJ from San Andreas saying, “Aw shit, here we go again.”

What Actually Happened

Over July 26 and 27, a coordinated campaign hit operational technology at more than thirty community water systems across Minnesota. State officials put the number at 36. The attackers got in through internet-connected programmable logic controllers, the small industrial computers that actually open and close things, many of which were reachable because they had cellular modems phoning home for remote management.

In most cases the intruders messed with settings that govern remote access rather than the machinery that treats and distributes drinking water. No water supply was compromised — that we know about. Several utilities dropped to manual operations, which is the OT equivalent of turning the car off and pushing it down the street in neutral. (This is not how you want to operate.) Federal and state investigators believe this bears the fingerprints of Iranian-affiliated actors, though attribution is preliminary and at least some investigators are (rightly) asking whether somebody wanted it to look Iranian.

To be clear, in cybersecurity, attribution is usually a nearly impossible task.

None of this came out of the ether. On April 7 of this year, CISA, FBI, NSA, EPA, DOE, Cyber Command, and Treasury put out a joint advisory (AA26-097A) on Iranian-affiliated actors exploiting internet-facing PLCs. They updated it on July 22, four days before Minnesota, expanding the scope from Rockwell/Allen-Bradley gear to Schneider Electric and Siemens controllers, and describing actors pulling project files off devices, modifying controller logic, and in at least one case… installing Dropbear SSH on a victim’s modem to keep a door propped open. (Holy shit!)

Everybody had a warning. The warning was absolutely as specific as you can make it. The warning had named vendors and also the ports.

And the nationwide municipal response was…

I don’t want to pick on Minnesota here. I’ve already made fun of Minnesota enough. They let Sam Darnold walk away after a 14-win season, so they could replace him with JJ McCarthy. Sam Darnold just won a Super Bowl. J.J. McCarthy looks like he’s about to lose his job to the half-eaten meatball sub otherwise known as Kyler Murray.

Anyway, I digress.

Minnesota is not special. Minnesota’s CISO said as much. Minnesota was just an early detector and the same activity is likely happening in other states. CBS reported activity across at least seven states. CISA’s acting director said the agency was tracking multiple potential incidents at local water utilities. It’s like if you see one roach in your kitchen. If you have one roach in your kitchen, no, you don’t.

We are not looking at a map of where the attack happened. We are looking at a map of where somebody happened to be looking. You found one roach. Trust me when I tell you this: you’re about to find dozens, if not hundreds.

There are roughly 50,000 community water systems in this country. If you tried to audit all of them, you would need a decade, a small army of cybersecurity engineers, and legal authority that does not currently exist. So when you read “36 systems,” the correct mental translation is not “36 systems.” It’s “36 systems, plus an unknown number where the water tower called for water, the well didn’t run, and everyone assumed it was just some technical glitch.”

Why Minnesota, Though?

This is where the narrative stops being purely about IT and goes into a mix between a Coen Brothers film and a Tom Clancy novel.

When I saw the list of affected towns, one town stood out to me: Plymouth.

Northrop Grumman’s Armament Systems business unit is headquartered in Plymouth, Minnesota, about ten miles west of Minneapolis. By the company’s own public description, the site handles development and production of medium- and large-caliber ammunition, precision capabilities for direct and indirect fire systems, lifecycle support for medium-caliber cannons, and miniature precision strike weapons for airborne platforms. Northrop’s Minnesota operations sit on more than $2.7 billion in multi-year military contracts.

This is not an office park with a whole bunch of cubicles. This is a place where kinetic stuff is happening. To put it into even clearer words: This is a fucking bomb factory.

And Plymouth isn’t alone. BAE Systems has been in Minnesota since the 1940s, when the Fridley plant made cannons for the Navy in World War II. BAE also opened a 247,000 square foot engineering and product development facility in Maple Grove last September for work on naval guns, launching systems, advanced munitions, submarine components, and combat vehicles. Lockheed, General Dynamics, and Honeywell all have Minnesota footprints.

Minnesota is a munitions state. It has been a munitions state since Franklin Delano Roosevelt was president.

Alright, now what you need to do, is ask yourself: What does a factory that is manufacturing large caliber ammunition require, in enormous quantities, every single hour it is running?

Water. Process water. Cooling water. Water for chemical operations. Water for the fire suppression system that your insurance carrier, your safety officer, and OSHA, will not let you operate a single shift without. Water for the thousand employees who need functioning bathrooms in order to be legally allowed to be in the building.

A munitions plant without water is a plant that cannot operate.

Do I know the IRGC’s motivations? No. Am I asserting that Iranian leadership drew a straight line from a specific municipal water company to Northrop Grumman’s loading dock? No, because I can’t know those things. But I don’t need to prove intent to make the point, because the point is the same no matter which way I phrase it: The input is targetable, and the input is mostly undefended. Whether or not Tehran connected those dots, the dots are sitting right there, and they’re publicly documented on corporate careers pages, in economic development brochures, and on the county GIS portal that shows you exactly which utility serves which parcel of land.

We gave them everything they need to target our defense industrial base.

Schweinfurt, But With The Internet

In 1943 the Eighth Air Force decided the German war machine had a chokepoint, and the chokepoint was ball bearings. No bearings, no engines. No engines, no aircraft. So we flew to Schweinfurt.

It didn’t go great. On the first October raid we lost 60 of 291 bombers, and The Army Air Force (before it was called the Air Force) called it Black Thursday. One run didn’t fully close the plants. We had to go back quite a few times, losing dozens more aircraft, and hundreds more young men. The strategic theory was sound. The delivery mechanism is what cost us hundreds of men — because the only way to touch a factory in 1943 was to fly an aluminum tube full of teenagers directly over it.

That was the constraint was the technology of the era. The idea behind it is as old as war itself: You don’t have to destroy the weapon if you can destroy the ability to make the weapon. Every strategist since Sun Tzu has understood this. The only question in any given century is what tools you have.

Iran cannot fly bombers over Minneapolis. Iran can, however, buy a Shodan subscription, find an exposed Siemens S7-1200, and pull the project file off it. That’s the whole system right there. Schweinfurt with internet access, at a cost of ISP fees and a few cybersecurity tooling subscriptions, with the added luxury of deniability. Also, when you’re dealing with offensive cybersecurity, you have the option to just sit there quietly for a year or more, and do nothing until the moment it matters.

I want to highlight the most important part of that because I think it’s something that we internalize. Cybersecurity events do not always happen the day movement happens. We interpret cybersecurity events as “this is the day when things went poorly.” The problem is our infrastructure can be infiltrated, and an attacker can just be dormant for months, if not years, if they so choose.

A bomber raid is an event. There are loud airplanes flying overhead. People know it’s happening. A pre-positioned implant is an option. The value of pre-positioning is that you get to choose the day to wreck shit, all at once. It’s highly coordinated. We, to our knowledge, know that Iranian elements began moving laterally inside Minnesota water systems last week. What we don’t know is how long they were dormant when they infiltrated and when those initial attacks happened that allowed them access. For all we know, it could have been years ago. I’m not trying to scare you. I’m just telling you how things actually happen.

The Farm System

The Atlanta Braves are one of the best teams in baseball right now, and it’s not because they have the highest payroll like the Los Angeles Dodgers. This is why the Atlanta Braves are objectively a superior baseball team. Anyone can go and buy a winning baseball team. It takes talent to develop a farm system capable of evaluating, drafting, and developing young baseball players.

Atlanta doesn’t win because of any one player. Atlanta wins because of a farm system, a scouting apparatus, and a development pipeline that most fans don’t understand. The parent club in Altanta gets the banner. The parent club gets the highlight package. But the reason the parent club exists in a competitive state, year over year, is a network of unglamorous facilities in unglamorous towns staffed by people making unglamorous money. There are things happening in Gwinnett County, Georgia, that most Braves fans will never understand or think about.

Allow me to connect the metaphor for you. The farm system is your downstream subcontractors and everything in the supply chain that has to work. Lockheed only makes 35% of the parts on the F-35. The other 65% are happening because of integration partners.

The American defense industrial base is exactly the baseball farm system. The prime contractors are the parent club with the big name players. But underneath the big city, sit tens of thousands of suppliers, and underneath those sit the actual physical substrate, the water district and the co-op and the municipal power authority. None of those entities have ever once been told that they are a component of national defense.

Also, it’s perfectly reasonable for them to not recognize their position in the farm system. If you live in a town of 6,000 and your job is to keep chlorine under control, and get the bills out on the fifteenth — at no point in your career has anyone informed you that you are logistically upstream of a 30mm anti-UAS cannon. In fact, you’d have to be kind of crazy to think of your position as integral to defense operations. Because your job is just to get the bills out in time.

Meanwhile, in a building in Tehran, somebody has absolutely made that connection, because making that connection is literally that person’s whole ass job. Tehran has to fight us asymmetrically because they don’t have a navy that can get across the ocean.

This is the human perception gap. And it’s not because people are stupid. It’s a completely rational response to the information available. Nobody looks at the water treatment plant off the county road and thinks “military target.” This is just a natural by-product of having Americans live in a state of perpetual bliss. Even during the height of World War II, American cities weren’t being bombed. We don’t think of ourselves as military targets because we’ve never experienced being military targets.

And now… Weaverville

I used to live in Weaverville, North Carolina. It’s in Buncombe County, a little north of Asheville, sitting up on a ridge at about 2,100 feet. It’s small a fuck, but they do have a newly built, big ass Wal-Mart. Population 4,567 at the 2020 census, in case you’re wondering. The water system serves about 8,100 people once you count everybody outside the town line.

I love Weaverville. One day I might go and retire there. There are a couple of cafes. There’s a pizza place right there on Main Street. There’s also this little brewery that just popped up, so you can grab a couple beers and then walk over to the pizza joint. People move to Weaverville to hike, to slow down, to have a garden, to not be in a city. It is the platonic ideal of a small Western North Carolina mountain town and I have nothing but affection for it.

With all that said, Weaverville is not equipped to repel a nation-state actor. I want to say that as non-judgmentally as it’s possible to say it. It is not a criticism of a single person who works there. They’re just not thinking about it, because the biggest threat to Weaverville is… probably the Subaru Crosstrek. Look, I’m not saying they’re bad cars, but really… come on. It’s just a lifted Impreza with plastic body cladding. Stop paying all the extra money for that.

I did a surface-level look at the public-facing services on Weaverville’s website. COTS municipal billing portal. Standard small-government stack. There is absolutely nothing in there you’d see in a federal enclave. Which, by the way, is defensibly correct on their part, because the requirement they were solving for was “Let residents pay their water bill.” They met that requirement, cheaply, with a product built for exactly that.

Nobody in Weaverville chose a vendor based on FIPS 140-3 validation. Nobody in Weaverville has a CISO. Nobody in Weaverville has a SOC. Weaverville has a Public Works Department with one phone number, and if you call it, and woman named Donna answers. She is extremely friendly, and her kids went to the same middle school I went to many years ago. We love Donna. Shoutout to the real MVP, Donna.

You know what else? Weaverville has already lived through losing its water. In the fall of 2024, Hurrcane Helene came through and the entire region went to boil advisories and distribution points, people hauling containers to the community center and the middle school to get drinking water. They know exactly what a week without functioning water does to a town. You aren’t telling the citizens of Weaverville anything they haven’t done before.

They just did it because of a hurricane, which is a thing that is easy to see coming, because it’s the size of two states, and is predictable-ish. Cyber-attacks from Iran are something they’ve never thought about.

Ready for another insane fact? Roughly 90% of America’s community water systems serve fewer than 10,000 people. Depending on how you count it, that’s like 46 million Americans who are served by a woman named Donna on a phone number you can call, in small-town America. That’s 10,000 Donna’s between us and Iran. Only a few Donna’s need to fail the social engineering test.

Let’s be real. Donna isn’t going to pass that test. She’s too friendly.

By one commonly cited estimate, only about 20% of water and wastewater systems maintain what I can charitably call “a minimum cybersecurity policy” — if we’re comparing it to auto insurnace. A 2024 EPA inspector general audit found close to 100 drinking water systems serving 26.6 million people carrying critical or high-risk vulnerabilities. The March 2024 EPA report found the greatest hits of security failure: default passwords still in place, credentials never revoked for departed employees, shared logins for entire staffs.

Like I said, Donna is the one running this organization. She’s wonderful. But her Roku password? It’s Roku1234.

There are thousands of little towns just like Weaverville, and there are thousands of women just like Donna. We love Donna. Donna should not be making cybersecurity decisions, and in many cases, she is. That’s not meant to be an insult. It’s just who we are as a country.

But if you want the best biscuits of your entire life? Call Donna.

Now I’m going to do that thing where I sound like I’m advocating for “big mean government.”

I understand the instinct push back against the government. When somebody says “the federal government should be involved in your town’s water utility,” a certain kind of American hears a mandate, and the kind of DC-metro consultants who wear Patagonia vests year round. Along with any fashion sense, these people come with a steep fee.

To which I say… Fine. Look at what the absence of involvement has produced.

The EPA is the designated risk management agency for the water sector, and GAO has been telling them since 2024 that they need an actual national strategy and that they should figure out whether they even have the legal authority to require anything. In “Federal Government Speak,” this is one director talking to another director and saying, “Hey, this is your fucking job.”

Cybersecurity in the water sector is, functionally, voluntary. Systems prioritize the mandatory thing, which is clean and safe drinking water from contamiants, poisons, chemicals, etc — because that’s what they get fined over. The EPA does not have the funding to prevent cyber attacks. How do I know this?

Last August the EPA announced roughly $9.5 million in cyber grant funding for public drinking water systems. Nine and a half million dollars, for a sector of 50,000 community systems. And systems serving fewer than 10,000 people, which is to say 90% of them, couldn’t apply. $9.5 million is what you pay a competent middle reliever in Major League Baseball for a season of work.

That is not big mean government. That is not red tape strangling the little guy. That’s a laughably small amount of money, aimed at the entities that needed it least, in a sector we have decided… cybersecurity is somebody else’s problem.

The libertarian bros of the internet will assume that this framing is a choice between the government being involved and freedom. The actual choice is between American government involvement and Iranian government involvement. Weaverville does not get to opt out of being a target of the IRGC. So either we make the choice to defend Weaverville, or the IRGC will make the choice to attack Weaverville.

Ahem. Clears throat loudly. Paperwork is not cybersecurity

I feel like I’ve been doing this a lot in the past several days, and I’m just going to keep on doing it until the federal government recognizes that it’s a problem.

I’m a big fan of The Wire, and there’s this scene in The Wire that reminds me of the situation we’re in. The political leadership of Baltimore wants crime statistics in Baltimore to go down. The functional way to go about doing something like that would be; investments in education, helping addicts get substance abuse treatment, investments in vocational training so people get jobs instead of committing robberies, looking at programs that reduce recidivism by making sure people who get out of jail are less likely to go back to jail… You know, functional stuff.

At the Baltimore Police Department, the easy answer was just to fake the stats. Rawls and Burrell looked at the numbers and said, if we just change the way we report crime stats, then crime will go down. Everyone up the chain gets what they need on paper, and the actual conditions on the ground either stay identical or get worse. The only person who suffers is the one who insists that measurement of crime is necessary for their personal politics.

In federal cybersecurity, the easiest way to make your industry look more secure is to juke the stats. I don’t think this is done maliciously. This is just something the government does because people in government are adept at producing spreadsheets. So we build these entire control catalogs, and then we require people to make attestations against these catalogs. If you do it right, within 12 to 18 months, you have created an entire sub-economy of people who are extremely good at producing documents that, on paper, demonstrate cybersecurity.

Of course, these are people who have never logged into the systems that they’re auditing. I have watched million-dollar consulting fees and “security postures” that consisted of beautifully formatted SSPs and diagrams that were visually stunning. Mind you, none of that shit worked, but it looked great.

If you take that exact model and you drop it on a town of 4,500 people, you won’t get comprehensive cybersecurity. Instead, you’ll have some local public works director who now has an additional chore to do on top of the other compliance chores they already do. And so what will happen is at like 4:30 on a Friday, when they’re facing a deadline, they will pretend to do their chores, just in the same way my children try to pretend to do their chores.

Paperwork is not cybersecurity, in the same way signing pro bowl free agents is not a winning football team. Advertising that you signed a big contract does not mean that, functionally, you will be a better football team. It just means you signed a big contract. This is why the Dallas Cowboys haven’t gone to the Super Bowl since 1996.

Cybersecurity isn’t magic. It’s just the auditable state of the machines running your software or firmware. That’s the whole shebang. Never once in my professional career have I asked a software engineer, “Did you write down that you patched that vulnerability?”

The questions that matter are, in no particular order:

  • What is actually running in your IT environment, right now?
  • What is actually running in your OT environment, right now?
  • Which of those things has a known vulnerability?
  • Can somebody check that, from outside, at any moment, without a two-week engagement?
  • Can you prove it in a form a machine can read?
  • Is it easy?

If the answer to the last question is “no,” then you won’t have a functional cybersecurity posture. That’s because the answer to the last question determines whether or not any of the other questions will ever be asked. If cybersecurity compliance is a shitty chore, it will be done badly and late, and the people who will do that job resent you for asking them to do it. If it’s an easy button, it will get done.

Kenny Powers didn’t stop being a professional baseball player because he was a piece of shit, racist, xenophobic, homophobic asshole. He stopped playing baseball, because baseball gave him access to money, and it made him believe that the hard work that he’d done in the past would suffice for hard work in the future. That’s why he was capable of going to the minor leagues, rebuilding himself, and then making another run at the major leagues. Attestation is Kenny Powers describing his fastball. An auditable machine state is the actual radar gun.

The whole point of the show Eastbound and Down is that you can’t trust Kenny Powers. Kenny Powers was a good baseball player. The problem is you can’t trust Kenny Powers on his own. You have to put Kenny Powers into a system that allows him to succeed, because if you don’t have a system around him that makes it easy for him to play baseball, he will produce problems for your organization.

The product thing, since it’s shameless self-promotion.

My company builds cybersecurity compliance software. If you think that means I need to discount some of the things I’m saying, that’s fine. I just want you to know it up front rather than pretend like I walked into this conversation by accident.

ACTA exists because I got tired of watching organizations pay enormous sums for documents. It reads cloud architecture and produces machine-readable compliance results. It’s instant-on, not a 12-week onboarding followed by a phalanx of consultants with spreadsheets. ACTA performs continuous vulnerability checking rather than an annual snapshot. The output is structured data a machine can verify, not an Excel sheet a human can get wrong.

There’s a second piece here because I want to make sure that I’m not using any kind of fuzzy language about the kind of vendor that we are. ACTA is an IT tool. It is not an OT tool, at least today. We do not talk to your PLCs. We are not going to tell you whether somebody modified an Add-On Instruction on your Allen-Bradley controller. (For those of you who even know what an Allen-Bradley controller is.) The Minnesota attack was (mostly) an OT attack, and I’m not going to sit here and pretend that ACTA wouldn’t have protected all these compromised Minnesota water utilities.

What I’m saying is that we see a market gap here, and from a business perspective, I think it makes a lot of sense for my company to at least attempt to be in that market. We do, after all, have an adjacent product, although we don’t have a roadmap for getting into the OT segment at this point. It could be us extending down the ACTA cyber product, or it could just be somebody else. Next year I’ll read about their product meeting this market demand, and I’ll feel dumb for not building the product in time.

Here’s my point: I don’t care who does it. I care about this because I understand how important it is. Right now, the alternatives for a small town like Weaverville are this: You can either do a six-figure assessment and produce some spreadsheets, or you can do nothing. Today, that answer is nothing for pretty much every small town in America, because nothing is exactly what they can afford.

What we need is a price point that fits the product, and right now this product is an OT fever dream. Until we can get to a price point, everything else doesn’t really matter.

Here’s what I think we need.

I don’t think we need a mandate with a checklist. I think we need a mandate with a turnkey kit.

Give small utilities hardened reference configurations they can actually deploy, the way DISA STIGs and hardened container images work in the federal space, except free and pre-built rather than a 300-page PDF. Give them a default answer to “how should this be set up,” so that they don’t need to think about it.

Then the hard part: You need to fund it for the systems that serve small towns, which means fund it at 90% of the sector, instead of explicitly excluding them from the one grant program that exists. I say this because that grant program was a stupid decision. I understand that they were trying to exclude any kind of small-town politics and fraud that may go on, but you can’t just assume that these small towns are a black hole for money. That’s unfair to them and also hurts our national security.

Donna isn’t malicious. She’s just incapable of doing the thing you want her to do.

Make the audits automatic, continuous, and machine-readable, so that the town doesn’t have to hire an expert to find out if it’s exposed. The utility should not have to know what a Modbus port is. The tool should know.

And tell them. Just tell them. Send somebody from the state to the county association meeting and say, in a loud Southern accent, “You are in the defense supply chain. Here’s why. Here’s what to do about it. Here’s who to call if you see some bullshit. It’s free.” The perception gap closes with communication.

There has been no 9/11 for cyber. Yet.

Great news. The thing that we don’t want to happen has not happened yet. We have not had the 9/11-scale cyber event. Nobody has died in large numbers because a control system got flipped. Every incident so far has been a near-miss, a warning shot, or a proof of concept. Americans are great at ignoring a near-miss and pretending that it wasn’t exactly what it was.

This is where I have to at least navigate the current politics of the moment because we are in a war right now with Iran. You can call it a conflict if you want to, and it makes you feel better, but if Iran thinks we’re at war, then we’re at war. They have demonstrated a very real capability, and a willingness, to reach into our municipal infrastructure and fuck it up. Federal agencies published the first advisory in April. They updated it on July 22. Minnesota happened on July 26. That’s four days later.

So we can’t say we weren’t told this was going to happen because we were told this was going to happen. We had specific vendor names and ports. The reason it happened is because nobody listened, and the people who were listening had no mechanisms or budgets or personnel to act on the warnings. Our policy apparatus is excellent at producing warnings and useless at producing fixes.

The arsenal of democracy still has a glass jaw. The difference between when I wrote my original post in November, and now, is that somebody has walked up and throw a punch. It wasn’t a square punch to the middle of the jaw, but it was enough of a punch that we should pay attention.

Iran is going to come back. They’ve got their hands up and they’re in the ring with us. The next punch they throw may be square and could break your jaw. And we may get our hands up in time to block a punch. I sure hope we do.

I’d like it to be the second option. It probably won’t be. I think that we should have been training metaphorically a long time ago. You can’t train when you’re in the ring.

Sources