$100 Million CFO Puts a Price on Executive Security

security men with car

Highlights

Executive security is shifting from a discretionary perk to a formal enterprise risk category as companies spend more on private aviation, drivers, residential surveillance and cyber protection.

CFOs still lack a common framework for pricing executive concentration risk or measuring how much each security control reduces potential operational, financial and reputational loss.

The real test is not whether perks like private jets look excessive, but whether their incremental risk reduction justifies its cost compared with less expensive alternatives.

Companies are pouring more money into private jets, personal drivers, home surveillance and cyber defenses to protect senior leaders. But few can say exactly how much risk that spending removes.

    Get the Full Story

    Complete the form to unlock this article and enjoy unlimited free access to all PYMNTS content — no additional logins required.

    yesSubscribe to our daily newsletter, PYMNTS Today.

    By completing this form, you agree to receive marketing communications from PYMNTS and to the sharing of your information with our sponsor, if applicable, in accordance with our Privacy Policy and Terms and Conditions.

    Between 2023 and 2024, for example, Intel Corporation expanded its security spending by over 8,000%, from $3,000 to around $250,000; while Lockheed Martin Corporation increased its security spending by 798%, with the company’s 2025 proxy statement disclosing that $1,194,805 of CEO compensation is allocated to security, with an additional $928,379 for personal use of corporate aircraft. Alphabet, Amazon, Meta, Nvidia and Palantir have all increased their executive protection budget by more than 10% year on year, per a Financial Times report. Meta in 2025 alone spent $27 million keeping CEO Mark Zuckerberg and his family safe.

    Those executive security spend numbers, when taken together, have only continued rising during fiscal year 2026 for public companies. But while finance teams have models for currency shocks, liquidity shortfalls, cyberattacks and supply-chain interruptions, corporate security, which protects people, facilities, information and business continuity, still frequently makes its case with incident counts, threat assessments and professional judgment.

    That puts CFOs, even mid-market ones, in unfamiliar territory. They are being asked to assign a value to preventing an event that may never happen, but that if it were to happen could disrupt operations, unsettle investors and expose the company to losses far beyond the physical harm to one person.

    See also: The $100 Million CFO Rewrites the Rules on Legal Spend 

    Executive Security Is Becoming a Key Risk Function But Lacks a Common Number

    The biggest change is not that executive protection budgets are rising. It is that finance leaders are beginning to recognize CEOs and other senior executives as concentrated corporate assets whose loss can interrupt strategy, financing, customer relationships, regulatory negotiations and investor confidence simultaneously.

    The modern corporation has spent years turning uncertainty into measurable risk. Cybersecurity teams report vulnerabilities, attack volumes, recovery times and maturity scores. Treasury models changes in interest rates and cash availability. Insurers assign prices to fires, lawsuits, kidnappings and operational interruptions. Even reputational risk is increasingly tracked through customer behavior and market sentiment.

    PYMNTS Intelligence data in the 2026 Certainty Project found that more than 8 in 10 mid-sized firms operatingunder high uncertainty missed their 2025 performance targets; high uncertainty also led to slimmer revenue and thinner margins. Looking ahead to this year, 35% of high-uncertainty firms expect shrinking revenue.

    Executive security has no equivalent unit of account for measuring the impact of uncertainty. A company can calculate what it spends on guards, armored vehicles or aircraft. It is much harder to calculate how much enterprise risk those measures remove. A threat may be credible without being probable. A protective measure may work precisely because nothing happens. And the gravest potential losses — from interrupted leadership to compromised negotiations — may never appear in an insurance claim.

    That makes executive security especially vulnerable to budget distortion. Companies may underspend because the previous year was quiet. They may overspend after a highly visible attack. They may benchmark against peers whose threat profiles, operating footprints and executives bear little resemblance to their own.

    The finance problem is not simply finding more money for protection. It is determining whether the proposed controls are proportionate to the exposure.

    Corporate aviation, for example, is where the financial discipline of executive security is most likely to be tested. Aircraft use combines legitimate business needs with one of the most visible symbols of executive privilege. Companies may require CEOs to use corporate planes for security, personal safety and efficiency, including for personal travel. Proxy disclosures increasingly make those mandates explicit.

    The same logic applies to personal drivers. A trained driver may provide route planning, threat detection and emergency response that a conventional car service cannot. It may also become an expensive convenience if the company has never specified the risk it is intended to mitigate.

    Read more: The $100 Million CFO Doesn’t Keep Score. They Call the Plays.

    Finance Needs a Security Rate of Return

    Corporate security has become too expensive to defend with anecdotes and too important to treat as an executive perk.

    Corporate security cannot prove its value simply by reporting that no executive was attacked. The CFO’s role in the new security environment is not to second-guess every threat assessment or reduce human safety to a spreadsheet. It is to make sure the company knows what it is protecting, what failure would cost and why the measures it has chosen are better than the alternatives.

    A defensible program should survive a counterfactual: What would the company do if this particular service were unavailable, and how much additional risk would it actually accept?

    Companies already gather much of this information. Security teams monitor online threats, travel patterns, protests, criminal activity, geopolitical instability and the availability of executives’ personal data. Cyber teams track account compromise, phishing and data leakage. Human resources and legal departments know where labor disputes, litigation and public controversy may elevate risk.

    What is often missing is the final conversion into financial terms. The companies that manage executive security most effectively may not be those spending the most. They will be the ones capable of answering the question every CFO ultimately asks of any investment: How much enterprise risk does this dollar remove?