iStock-808145472.jpg

Executive Protection Insights & Articles | ISCG

“Our mission is to help you accomplish yours”


Three Different Institutions Now Have a Say in Your Corporate Executive Protection Program

Most executive protection and corporate security managers have never sat in a compensation committee meeting, read a proxy statement, or spoken with a proxy advisory analyst. There's usually no reason to. But decisions being made in exactly those rooms are now shaping EP budgets, staffing levels, and whether a program survives the next proxy season, and almost none of that is visible from the operational side of the job. This is a plain explanation of what's actually going on, and why the documents your program produces matter more than most executive protection managers realize.

Who's Actually in the Room

Three different institutions now have a say in your program, and none of them think about security the way you do. The SEC requires public companies to disclose, in dollar terms, any “perquisite” provided to a named executive, personal benefits beyond salary and standard compensation, in the proxy statement's Summary Compensation Table. Security benefits, a driver, residential security systems, secured transportation, sometimes private aircraft use, increasingly get classified into that bucket unless the company can show they're integral and necessary to the job itself, not a personal comfort.

Institutional Shareholder Services, known as ISS, is the dominant proxy advisory firm. It doesn't run the company or sit on the board, but a large share of institutional shareholders vote the way ISS recommends on say-on-pay, the advisory shareholder vote on whether an executive's total compensation looks justified relative to performance. When a security line item is large, and it increasingly is, Meta spent $27 million protecting Mark Zuckerberg in 2025 alone, it can visibly inflate reported total compensation and drag a say-on-pay vote toward a negative recommendation. ISS has explicitly cited “excessive security perquisites” as a factor behind several such recommendations.

The IRS runs a completely separate track. Its rules determine whether the value of an executive's security benefits counts as taxable personal income to that executive, or can be excluded as a working condition fringe benefit under what's called an overall security program. That exclusion is only available if the company can document a bona fide business-oriented security concern, a specific, fact-based reason to believe this particular executive faces real risk, not a general statement that executives in general are targets.

The Two Tests Which Can Decide Your Program's Fate

Put simply: the IRS asks whether there's a documented, specific reason this executive needs protection, before it will treat the cost as a legitimate business expense rather than personal income. ISS, as of its 2026 policy update, is now asking almost the same question before it will decide whether to flag the cost as excessive in a say-on-pay recommendation. Two institutions that have nothing to do with each other, one built around tax law and one built around shareholder voting, have converged on wanting to see the same kind of evidence: a real, documented, particularized security assessment, not a generic justification.

Specifically, ISS's 2026 guidance states it generally won't object to even high-value security perquisites if the company discloses a reasonable rationale for the spend, evidence of an internal or third-party security assessment, and a description of how the program connects to shareholder interests, meaning business continuity and company value, not just personal safety. Extreme outliers without that kind of disclosed justification still draw real scrutiny. The bar for keeping a security program out of trouble just got a lot more specific, and a lot more procedural.

Why Your Threat Assessment Is the Document That Actually Matters Now

Here's the part that affects you directly. Most companies with an executive protection program don't have a security assessment that would hold up to either test, let alone both. Where one exists at all, it's usually written the way practitioners are trained to write it: focused on routes, residence hardening, staffing levels, technology, and travel protocols, built to justify a budget internally, not to survive review by a tax examiner or a proxy analyst who has never heard of an advance.

That kind of document rarely states, in terms a non-security reader would recognize, what the specific, fact-based basis for concern actually is for this individual, how each program component maps back to that particular risk rather than a general one, or how the program protects the company's continuity and shareholder interests rather than just the executive's comfort. When that connective language is missing, boards end up in exactly the position now being written about in governance and legal circles: spending real money on protection, disclosing it because the rules require it, and still absorbing a negative say-on-pay vote or a shareholder challenge, not because the protection was unnecessary, but because the reasoning behind it was never actually written down in a form built to be scrutinized.

This is also why a one-time write-up doesn't hold up well under either test. Both the IRS's business-concern standard and ISS's disclosure expectation reward a assessment that's been independently reviewed and periodically refreshed, not a document commissioned once, years ago, and never revisited as the executive's public profile, the company's risk environment, or specific threats have changed.

What This Means for the Job

Executive protection has always been judged internally on whether an incident happened. It's now also being judged externally on whether the program can produce, on request, a documented answer to why it exists, one specific enough to satisfy an IRS examiner and clear enough to satisfy a proxy advisory analyst, built from real assessment methodology rather than boilerplate. That's not a legal or compliance task bolted onto the job. It's a natural extension of the same skill set protective intelligence and threat assessment already require, applied to an audience most EP managers have never had to write for before. The managers and consultants who start doing that well are going to be the ones whose programs survive the next round of scrutiny intact, and whose value to the organizations they protect goes well beyond the operational floor.

Walter Gaya