Bank of America Is Buying British Cybersecurity Firm MDSec
The US banking giant is acquiring a 65-person UK security consultancy, deepening its foothold in northern England and adding offensive security expertise to its in-house defences.

Key points
- Bank of America announced plans on Thursday to acquire MDSec Consulting Limited, a UK-based cybersecurity firm headquartered in Macclesfield, England.
- MDSec employs approximately 65 cybersecurity professionals and provides hands-on technical security consulting.
- The deal is expected to close in the fourth quarter of 2026, pending regulatory approvals.
- Financial terms were not disclosed.
Bank of America is buying MDSec Consulting Limited, a technical cybersecurity consultancy based in Macclesfield, England. The Charlotte, North Carolina bank announced the deal on Thursday. No price tag was made public.
For readers unfamiliar with what MDSec actually does: the firm offers hands-on security testing, meaning its staff break into clients' own systems (with permission) to find weaknesses before criminals can. That kind of work, sometimes called offensive security or penetration testing, is in high demand from large financial institutions that need to know exactly how hard their defences are to crack.
MDSec has around 65 staff. Small, by corporate standards, but tightly specialised.
Why does Bank of America want a small British firm?
Geography and expertise are the two answers. Bank of America already employs more than 1,400 people in Chester, a city in north-west England close to Macclesfield. The bank also runs a cyber threat operations centre there, a dedicated team that watches for attacks around the clock. Adding MDSec to that cluster makes obvious sense.
On the expertise side, MDSec co-founder Dominic Chell is well known in security research circles. The firm has published respected work on red-teaming techniques, where security professionals simulate real attacker behaviour to stress-test an organisation's defences. That kind of capability is not easy to build from scratch inside a bank.
Bank of America's chief information security officer, Kris Fador, said the bank had "long admired the exceptional ability of the MDSec team."
Chell, for his part, framed the acquisition as a chance to scale up. "Joining one of the world's leading financial institutions, one that reflects our culture of innovation and technical excellence, gives us an incredible opportunity to take that ambition to the next level," he said.
What does this mean for MDSec's current clients?
That is the open question. MDSec has historically worked with clients across industries, not just banking. Once the acquisition closes, those relationships will sit inside a major competitor to some of those clients' own banks. It is worth watching whether MDSec continues to take outside work or shifts entirely to internal Bank of America projects. Neither the bank nor MDSec addressed this point in their announcement.
The deal still needs regulatory sign-off and is not expected to complete until late 2026, as the table below summarises.
| Detail | Facts |
|---|---|
| Buyer | Bank of America (Charlotte, NC) |
| Target | MDSec Consulting Limited (Macclesfield, England) |
| MDSec staff | Approximately 65 |
| Deal value | Not disclosed |
| Expected close | Q4 2026 |
| Condition | Regulatory approvals required |
First reported by SecurityWeek, the announcement is a reminder that large banks increasingly treat security talent as a strategic asset worth buying outright, rather than contracting out.



