The New Calculus of CEO Security


As executive protections expand, boards may need to take a closer look at how security needs are assessed and overseen.
Key Takeaways:
- A new study shows that a majority of firms lack a former CEO security program or board oversight role.
- Security needs can differ substantially, making informal processes like peer-to-peer benchmarking difficult.
- Boards should consider an official security assessment among other measures to determine risk and protection levels.
How Boards Are Rethinking CEO Security, Spending, and Oversight
Threats targeting the CEO had increased over the past year, and the board had approved new security measures as part of the perquisites package. But the directors weren’t sure about their analysis: Benchmarking could tell them what peer companies were providing, but not whether their own security package matched the risks their CEO faced. Were they adequately protecting their CEO—or spending in ways that didn’t match the actual risk?
“While companies are devoting more resources to executive protection, the governance processes around it remain surprisingly informal.”
This uncertainty appears to be widespread: A recent study found that just 10% of the firms surveyed had conducted a formal CEO threat assessment, and 73% relied solely on informal judgment to determine the executive’s security needs. The same study found that 65% lacked a formal CEO security program; 58% had no formal board oversight role; and 37% of boards never received security updates. Yet against this background, executive protections are expanding. Among S&P 500 companies, 37.8% provided security perks in 2025, up from 23.6% in 2021—an increase of over 50%—while the median cost of these security packages more than doubled. While companies are devoting more resources to executive protection, the governance processes around it remain surprisingly informal.
The trouble is that executive security may be particularly difficult to gauge informally. Security needs can differ substantially depending on an executive’s public profile, industry, travel, and specific threats—factors that aren’t necessarily captured by peer-company benchmarks. Irv Becker, vice chairman of executive pay and governance at Korn Ferry, says that commissioning an official security assessment may make sense as “the first step in justifying a change to their current policy.” Rather than simply showing directors what other companies spend, an assessment can identify the risks the company is actually trying to address—and help explain why one executive’s protections may look quite different from another’s.
The structure of the protection itself is evolving, too. Todd McGovern, global leader of total rewards at Korn Ferry, says one approach is to distinguish between a baseline level of security and additional temporary protection as needed. “Boards should consider what the baseline level of security should be, and then whether it needs to flex because of circumstances,” he says. An international trip, for example, could change an executive’s risk profile temporarily. Personal travel choices can affect the equation as well, particularly when they make protection substantially more complicated or expensive. “If a company is spending twice as much on security because of the choices an executive is making,” McGovern says, “it’s fair to ask whether that’s the best use of shareholder resources.”
As it happens, even the regulatory distinction between a security perk and a business expense may soon be reconsidered. Under current SEC guidance, security at an executive’s residence or during personal travel generally counts as a perquisite, even when the company requires it for security reasons. But SEC Chair Paul Atkins recently said that “the world has changed” since that guidance was adopted in 2006 and called for modernizing the agency’s treatment of executive security. Broader executive-compensation disclosure reform is slated for a proposed rule in October, potentially providing a vehicle for such a change. Becker says the issue could have disclosure implications: “The SEC is looking at whether some of these security expenses should be treated as a business expense rather than a perquisite—and if so, it wouldn’t have to be disclosed,” he says. The potential shift underscores how much the security calculus has changed: What appears in the proxy statement as an executive benefit may increasingly be viewed as a basic cost of protecting the business.

If anything, treating security as a business necessity may strengthen the case for spending more when the risks warrant it. Threats to corporate leaders have become a bigger concern, and investors appear to recognize the stakes: 97% of institutional investors said physical protection for executives at companies in their portfolio was important. “Security is important—it could be life or death,” McGovern says. “You shouldn’t feel bad paying for it if it’s aligned with shareholders’ interests.”
Learn more about Korn Ferry’s Executive Pay and Governance capabilities.
