@marbunasells-1793 Since your CEO needs to be a Global Admin and to enable MFA, you need Global admin privileges, I tested/confirmed if a Global admin can delete another Global admin, and found that it's possible. However, if your IT-man accidently deletes your CEO/ any other user from Azure AD, you can easily recover that deleted user if it's within 30 days. If it's greater than 30 days, neither you nor Microsoft support can restore a permanently deleted user.
Restore or remove a recently deleted user using Azure Active Directory
If you'd like to restrict administrator role permissions you can view our documentation for our built-in roles.
Please let me know if you have any other questions. Thank you for your time!
If any reply/answer helped resolve your question, please remember to "mark as answer" so that others in the community facing similar issues can easily find the solution.