The McNamara fallacy is the error of treating what can be measured as the whole of what matters, and progressively discarding everything else. It is named after Robert McNamara, US Secretary of Defense during the Vietnam War, whose reliance on body counts as the measure of progress became the standard example.
The sociologist Daniel Yankelovich described the progression in four steps. Measure what is easy. Disregard what cannot be measured. Presume what cannot be measured is unimportant. Conclude that what cannot be measured does not exist.
Security tools produce enormous quantities of countable data. Alerts, findings, blocked connections, agent check-ins, scan results. All of it arrives automatically, at high volume, in a format that goes straight into a chart.
The parts of the programme that resist counting arrive by contrast slowly and by hand. Whether the exercise actually stressed the response plan. Whether the team has the skills for the estate it now runs. Whether a third party fixed what it promised. Whether the budget bought resilience or shelfware. Whether policy exceptions are being granted faster than they expire.
The measurable half is not the more important half. It is the more automatic half. Over a few reporting cycles those get confused.
A programme whose entire metric set derives from tool exports. Nothing about people, exercises, third parties, audit closure or spend.
A steering committee that discusses the numbers it has for forty minutes and the risks it cannot quantify for five.
An investment case built entirely on what the current tooling can evidence, which systematically favours more of the same tooling.
Measure the hard things badly rather than not at all. A quarterly manual entry with a named owner and evidence attached is imprecise. It is also infinitely better than an absence, because absence gets read as zero.
Keep an explicit register of what matters and is not being measured, and review it. Naming the gap prevents step three of Yankelovich’s progression, which is where the real damage happens.
Treat manual data as first-class rather than as a stopgap. If it only exists in a side spreadsheet, it will lose every argument against an automated number.
From the blog