Executive Protection: Essential Business Expense or Taxable Perk? 

Recent Incidents Driving Focus on Executive Security

High-profile violence against business leaders has spurred companies to reexamine executive protection. The December 2024 murder of UnitedHealthcare CEO Brian Thompson was a stark wake-up call: Thompson was shot dead outside a Manhattan hotel in a targeted attack just before an investor meeting. Police indicated the suspect saw the killing as retaliation for perceived industry “corruption”. This tragedy underscored that corporate decisions can spark deadly resentment. In its aftermath, corporations began reassessing security protocols – some insurers even pulled executives’ photos from websites and weighed boosting protection to make their leaders less identifiable targets. 

Other recent incidents have similarly highlighted risks to executives and their families, prompting broader industry reflection: 

These cases, ranging from politically motivated home invasions to outright assassination, have made executive security a pressing concern in boardrooms. Companies are increasingly asking: How do we protect our people – and at what cost? 

Growing Threats to Corporate Leaders

Recent data confirms that threats against executives are on the rise. A 2022 Ontic survey of large U.S. companies found 88% of security and compliance leaders observed a dramatic increase in physical threat activity compared to a year prior. Nearly half of legal and compliance officers (44%) cited physical security threats to the C-suite and company leadership as a top concern for business continuity. In other words, protecting executives is no longer seen as a luxury – it’s becoming a core risk management issue for many firms. 

One major driver is the amplification of anger via the internet. Social media and online forums allow disgruntled individuals to single out corporate figures and rally others. In the five weeks following Thompson’s murder, analysts identified over 2,200 direct threats against CEOs in online posts. This “staggering” volume of threats shows how quickly online vitriol can translate into real danger. Indeed, Thompson’s killing was a “grim reminder that online vitriol, doxxing and targeted harassment can have real-world consequences.” Executives today face coordinated campaigns blending digital harassment (e.g. doxxing personal details, deepfake smear videos) with physical intimidation. For example, angry stakeholders or ideologically driven actors might publish a CEO’s home address or schedule, encouraging confrontations. 

This convergence of cyber and physical threats means executive protection now extends beyond bodyguards and gated homes. It involves monitoring online narratives, securing personal data, and preparing for “swatting” or other harassment. The risks are highly personal – stalking, kidnapping, and violent attacks – but they stem from an executive’s corporate role. As these threats grow, companies are grappling with how much security is enough to counter them, and where the responsibility lies. 

Request a Consultation​

Financial and Tax Implications: Business Expense vs. Perk

The rise in executive protection brings a tricky question: should these security measures be treated as a legitimate business expense or as a taxable perk for the executive who benefits? The answer has significant financial and tax implications for both the company and the individual. 

Business Expense Perspective

From a corporate standpoint, protecting key executives is a necessary cost of doing business – akin to insuring a critical asset. The sudden loss or incapacitation of a CEO can devastate a company’s stock and operations, so spending on prevention (security) is arguably in shareholders’ best interests. Many companies justify security spending by conducting regular threat assessments. For example, Meta (Facebook’s parent) disclosed it had “identified specific threats to Mr. Zuckerberg” as part of its annual security review – a rationale for the millions it spends to keep its CEO (and his family) safe. When framed as a business necessity, these costs are typically paid by the company and booked as corporate expenses.

In the United States, the IRS allows certain security costs to be treated as non-taxable “working condition fringe” benefitsessentially business expenses – if a bona fide business-oriented security concern exists. To meet this threshold, the employer must show a specific, credible threat to the executive (a “specific basis for concern,” such as documented threats of death, kidnapping or bodily harm).

Companies often hire independent security consultants to evaluate threats and recommend protections; if those recommendations are followed consistently, the IRS deems an “overall security program” is in place. When such a program exists, a large share of personal security costs can be excluded from the executive’s taxable income as a working condition fringe. In essence, the IRS acknowledges the expense is for the company’s benefit (keeping its leader safe), not a personal windfall.

Taxable Perk Perspective

On the other hand, regulators are wary of executives enjoying lavish benefits under the guise of security. The U.S. Securities and Exchange Commission (SEC) generally views personal security services as a perquisite (“perk”) that must be disclosed as compensation to shareholders. The SEC’s rules say a perk is any benefit with a personal aspect that isn’t strictly necessary for the executive to do their job. Security at an executive’s private residence or on personal travel clearly has a personal benefit, even if there is some business reason, and so SEC guidelines treat those costs as perks requiring disclosure. For example, installing a home alarm or providing bodyguards for the CEO’s family vacation must be reported in the proxy statement’s executive compensation tables if the values are above modest thresholds. This doesn’t forbid such security measures, but it does shine a light on them, allowing investors to judge if they are appropriate. It can also create tax consequences: if the security doesn’t meet the IRS’s strict “bona fide business threat” test, then the value of those protections is imputed as income to the executive(meaning the executive pays taxes on it, as if it were part of salary). In those cases, the company might still deduct the cost as compensation, but the executive bears a tax hit for the personal benefit. 

The line between business need and personal benefit can be blurry, which leads to debate. Companies sometimes argue that in today’s environment, “nothing is more critical to an executive’s ability to fulfill their duties than to be safe and alive.” By that logic, comprehensive security should be seen as integrally related to the job, not a fringe luxury. The SEC has historically been unconvinced, maintaining a narrow view of what’s job-critical. However, there are calls for regulators to update standards given the “significantly blurred” line between work and personal life for modern executives (who may be “working and available at all times” even from home). Until any rule changes, companies must navigate the current rules. Several have learned the hard way that failing to properly disclose security perks can lead to enforcement action. The message is clear: if a company pays for an executive’s personal protection, investors have a right to know. 

International Treatment

Outside the U.S., similar principles apply. In the UK, tax law provides a narrow exemption for employer-provided security if an executive faces a “very real threat” due to their work – typically threats from terrorists or extremists. A notable case involved Lord Hanson, a prominent British industrialist in the 1980s who had 24-hour security funded by his company. He argued he was under special threat from the IRA (Irish Republican Army) given his high profile and political ties. A tax tribunal accepted that Hanson’s situation was uniquely perilous and allowed the security costs as non-taxable, even though he hadn’t received a specific death threat. The ruling stressed that such exceptions are rare, and unless an executive can show evidence of a personal threat, security perks remain taxable. In practice, most countries’ tax authorities mirror the IRS stance: genuine security needs can be treated as business expenses, but absent clear threats, personal security looks more like a benefit to be taxed. Corporate governance codes likewise often require disclosure of perks, so global companies tend to err on the side of transparency. 

In summary, the financial treatment of executive protection hinges on demonstrating necessity. When a threat is credible and documented, companies can justify protection as a business expense (reducing tax burdens and shareholder criticism). But if an executive’s “protection” resembles chauffeured comfort with no clear risk, regulators will view it as compensation. This tug-of-war incentivizes firms to formalize security programs and keep records of threats – both to keep their leaders safe and to defend the legitimacy of those costs. 

Corporate Responsibility and Ethical Considerations

Beyond the accounting and rules lies an ethical question: How far should a company go to safeguard its executives, and does that duty extend to their families? From a corporate responsibility perspective, most agree that if an executive faces danger because of their job, the company has a moral obligation to mitigate that danger. A CEO is not just a private individual; they are the public face of the company, and any harm to them can have far-reaching consequences. Ethically, providing security is an act of duty of care – much like providing a safe workplace. This duty can become literal: when threats emerge (anonymous letters, angry protestors, stalkers), not acting could be seen as corporate negligence. Companies routinely beef up protection for executives in sensitive roles (e.g. defense contractors, pharmaceutical CEOs during drug pricing controversies) because they recognize a responsibility to protect their people when the job puts them in the crosshairs. 

However, the extent of that responsibility raises debate. Protecting the executive at work is one thing – but what about after hours, or the executive’s spouse and children? Many threats against CEOs do target their families, either out of malice or as leverage (kidnappers, for example, often prefer grabbing a family member). Ethically, if a threat actor has indicated a CEO’s family as a target, the company should respond accordingly. This might include installing security systems at the CEO’s home, providing guards for family members in high-risk periods, or covering secure transportation for the family. Such measures blur the line between corporate and personal, but they may be justified as preventative measures that ultimately protect the company’s interest (by keeping the CEO focused and unharmed). In practice, firms often do extend security to immediate family when credible threats exist – for instance, Facebook’s security program explicitly covers Mark Zuckerberg’s wife and children, and other companies quietly do likewise when risk dictates. The ethical rationale is that family members didn’t choose the public role, yet they bear the risk by association; providing them protection is seen as the right thing to do when danger spills over from the professional realm. 

Still, there are concerns about equity and precedent. Why should only the top executives receive protection? In a large organization, other employees or even customers can face threats (consider a researcher whose work attracts extremist ire, or a regional manager attacked by a disgruntled ex-employee). If the company pours resources into guarding the CEO’s mansion but ignores a lower-level employee who has a stalker, is that ethically sound? Companies must consider proportionality and consistency. Typically, the justification is that top executives are at uniquely high risk and are irreplaceable in the short term – but this can be a slippery slope. There’s also the matter of cost vs. benefit: extensive security is expensive, and those funds ultimately come from shareholders (or in nonprofits, from funds that could go to the mission). Ethically, a company should only spend what is reasonably required to mitigate real dangers, not indulge an executive’s preference for an entourage. Transparency helps here: if a CEO truly needs 24/7 protection, the board should be able to explain why. If they cannot do so without embarrassment, the expense might not be ethical. 

Another consideration is the privacy and autonomy of the individuals being protected. Some executives are uncomfortable with bodyguards or feel that heavy security creates a barrier between them and employees or the public. For example, an executive may worry that arriving with a security detail sends a message of elitism or fear. Companies have to balance respecting an individual’s wishes with fulfilling their duty of care. In some cases, boards have mandated security for a CEO despite their reluctance – essentially deciding that the risk to the company outweighs the executive’s personal discomfort or image concerns. 

In weighing these factors, questions arise that have no easy answers: 

  • Should a CEO’s family be guarded on the company dime if no direct threat is made, or only after a family member is targeted?
  • Is it ethical for a company to require an executive to accept protection (for instance, forbidding them from flying commercial or walking alone), or does that infringe on personal freedom?
  • Conversely, if an executive forgoes security to save money, and something happens, did the company fail in its moral duty?
  • Where is the line between prudent protection and excessive pampering? A secure car and trained driver might be justified, but what about armored vehicles or multiple residences with security staff?

These dilemmas force companies to continuously calibrate their approach. The goal is to keep people safe without losing sight of fairness and proportionality. It’s an ethical tightrope: too little protection can be irresponsible, too much can be indulgent or send the wrong message.

How Companies Approach Executive Protection

Corporate approaches to executive protection vary widely, influenced by the company’s culture, the executive’s profile, and the threat environment. Generally, approaches fall on a spectrum from minimalistic to highly comprehensive: 

  • Reactive & Minimalist: Some companies provide only basic security unless a specific threat emerges. They might rely on standard building security at headquarters and advise executives to be cautious, but not fund personal bodyguards or home systems absent evidence of danger. Under this approach, if an executive starts receiving threats or if an incident like a public harassment occurs, the company will then step in with measures (hiring a security firm, etc.). The downside is this may be “too little, too late,” as seen in UnitedHealthcare’s case where Thompson appeared to be unguarded when he was murdered, despite prior harassment signals on social media. After such events, even previously hands-off companies tend to rethink their stance.
  • Proactive & Comprehensive: On the other end, many large corporations take a proactive stance, especially for high-profile CEOs. Tech and social media giants are known for this. For example, Meta has an “overall security program” for Mark Zuckerberg costing $20+ million annually, including personal bodyguards, residential security technology, secure vehicles, and a private jet policy. Meta even provides a yearly pre-tax allowance (recently $14 million) specifically for Zuckerberg’s additional personal security needs. This approach essentially treats the executive like a head of state in terms of security detail. Other companies may not spend as much, but still mandate certain protections – for instance, requiring the CEO to use corporate aircraft for all travel (for security reasons), or having trained drivers and guards accompany them to public events. Some CEOs have security agents pose as personal assistants or drivers to maintain a low profile yet be close at hand. The comprehensive approach often extends to family: security consultants assess the routines of spouses and children, recommending precautions like secured homes, escort for kids to school in high-risk scenarios, and personal information scrubbed from the internet. While costly, this strategy aims to leave no gap exploitable by would-be attackers. Companies taking this approach argue that the cost of protection is justified by the potentially catastrophic cost of an unmitigated tragedy.
  • Hybrid & Risk-based: Many firms adopt a middle path – providing a baseline of protection and scaling it up or down based on threat level. For example, a company might cover a home alarm system and on-call security for its CEO at all times, but only deploy physical guards when traveling to certain regions or attending high-visibility events. If intelligence (or even social media chatter) indicates elevated risk – say, the CEO is receiving angry backlash over a controversial decision – the company temporarily boosts the security detail. When things calm down, it might scale back to avoid unnecessary expense or intrusion. This risk-based model tries to be efficient: protect when needed, but not create a permanent “security bubble” around the executive if it’s not warranted. It requires continuous monitoring of threat indicators. Some companies now use specialized intelligence services to monitor threats against their leadership in real time, so they can adjust security measures quickly as needed.

Different industries also have different norms. Financial services and healthcare firms have seen more threats in recent years (e.g. outrage at drug pricing or insurance denials), leading many to quietly bolster security for their CEOs and even other C-suite members. In contrast, a small tech startup might do very little until it grows and the CEO becomes better known. Geography matters too – executives operating in kidnap-prone regions (parts of Latin America, Middle East, etc.) are often given security training and protection as a matter of course, whereas a CEO in a relatively low-crime area might just get an alarm system and contingency plan. 

Some corporate approaches have faced scrutiny or pushback. When security costs skyrocket, investors and governance experts may question the necessity. For instance, Meta’s multi-million dollar security spending on Zuckerberg draws media attention annually, though the company defends it by citing persistent threats and his unique public exposure. In some cases, shareholders have raised concerns: Is the CEO really under that much threat, or is this an excessive perk? Companies that handle this well typically provide a clear justification – without divulging sensitive details, they might mention that professional assessments identified credible risks, and the board has deemed the security measures appropriate. By contrast, companies that have tried to downplay or hide these expenses have been met with regulatory penalties (as noted with the SEC’s crackdown on undisclosed perks). 

One approach that companies increasingly use to justify security programs is invoking duty of care and business necessity in official communications. Proxy statements often explain that the board requires the CEO to use certain security measures for the company’s benefit. For example, Amazon historically disclosed paying for security for its founder Jeff Bezos, noting it was for “business reasons” given his visibility as owner of media (The Washington Post) and other factors – essentially framing it as not just personal. Similarly, when other executives like Oracle’s Larry Ellison or Apple’s Tim Cook have security paid by the company, the narrative provided is that these leaders are vital to the company, and their protection is a corporate priority. 

In terms of successfully defending an executive protection program, one key is consistency. If a company provides a security perk to the CEO but neglects basic security elsewhere, it appears suspect. But if it’s part of a holistic security philosophy (where, say, the company also invests in workplace security, employee safety training, etc.), then executive protection is easier to defend as one element of the broader safety strategy. Some companies explicitly mention that executive security is part of an “overall security program” covering personnel and assets, aligning the CEO’s protection with the company’s general security framework. This language not only helps with IRS qualification, but also frames it as a matter of corporate policy, not individual privilege. 

Ultimately, approaches continue to evolve as threats do. The shocking nature of the UnitedHealthcare CEO’s murder has many firms rethinking even their previously modest security stance – better to be over-prepared than caught off guard. As one security expert put it, “Are there going to be copycats? That is unacceptable.” Companies are now experimenting with measures like scrubbing executives’ digital footprints, providing personal cybersecurity tools, and even crisis response plans for executive-targeted events. The trend is toward a more comprehensive view of executive protection – covering physical, digital, and reputational spheres – but implemented in a way that can be justified to stakeholders and regulators. Each company must find the balance that fits its risk profile and values, knowing that both excessive caution and excessive complacency have downsides. 

Request a Consultation​

Conclusion: Balancing Necessity, Cost, and Ethics

Executive protection is increasingly seen as an essential cost of doing business in a world where CEOs and other corporate leaders can become lightning rods for anger, activism, or criminal schemes. The very real risks – from assassination to harassment – make a compelling case that providing security is not about pampering executives, but about ensuring the continuity and stability of the enterprise. In that sense, reasonable security expenses should be viewed similarly to insurance premiums or cybersecurity budgets: a prudent investment to manage risk. The murder of a prominent CEO or the kidnapping of an executive’s family member are “black swan” events that companies must strive to prevent, and prevention has a price tag. 

To make this case convincingly, companies need to document and communicate the justification for executive security spending. Conducting independent threat assessments, as recommended by regulators, not only helps qualify expenses for tax exclusion but creates an evidence-based rationale that can be shared (at least in broad strokes) with investors. When shareholders see that a CEO’s security budget is based on professional advice and real threat data – not just on the CEO’s personal preferences – they are more likely to accept it as a necessary cost. In contrast, if security spending appears arbitrary or egregiously out of line with peers, it risks being viewed as an abuse of corporate resources. Transparency, within the limits of safety, is key. Companies often include explanatory notes in proxies (e.g., “Due to specific threats against our CEO, the board has authorized a security program for her protection”) – this kind of disclosure helps frame the narrative that the expense is essential. 

That said, there will always be gray areas and tough judgment calls. Companies and boards should continuously ask themselves thought-provoking questions to draw ethical and financial lines: How do we distinguish between legitimate security need and nice-to-have convenience? Are we periodically reviewing the threat level to scale security up or down, or has a temporary measure become permanent without good reason? At what point should an executive bear some responsibility for their own security (financially or otherwise)? For instance, if a threat diminishes, should the CEO eventually resume flying commercial, or is the company committing to a lifetime of private flights? Another question is how far down the org chart such protection should extend – should only the CEO and maybe a few top executives be covered, or should anyone facing credible threats (like a country manager dealing with organized crime extortion) receive equal attention? 

There’s also the issue of family protection: Is it an all-or-nothing proposition, or based on threat specifics? If an executive’s family members start to feel unsafe due to the executive’s role, does the company automatically step in? Some argue that offering to protect the family in crisis is part of respecting the whole person you’ve put in a risky position as CEO. Others worry that it opens the door to excessive spending or even potential abuse (e.g., could an executive request security for a family event that’s only tenuously related to a threat?). Clear policies can help here – for example, a company might codify that it will protect immediate family only if an articulated threat or incident warrants it, not as a routine perk. 

In the end, executive protection requires a delicate balancing act. It should neither be reflexively labeled a frivolous perk nor embraced with blank-check funding. The goal is to safeguard human life and well-being in a way that is responsible to the business and its stakeholders. As threats to corporate leaders continue to evolve, this conversation will remain active. Companies must adapt their security strategies while upholding transparency and fairness. Stakeholders – from employees to investors – will rightly ask: Where do we draw the line? 

Perhaps the most fundamental question is one of principle: What price do we put on safety, and who should pay it?The answer will differ by context, but by examining cases, data, and ethical norms, organizations can make more informed decisions. Executive protection, at its best, is about enabling leaders to lead without fear. Deciding how to provide that protection – and how to account for it – is a complex task that sits at the intersection of security, finance, and ethics. It challenges companies to protect both their people and their integrity. 

Contact us today to book a consultation
Email

info@sicurogroup.com

Website

www.sicurogroup.com

Phone

+971 4 363 5392