Bank of America Is Buying British Cybersecurity Firm MDSec
The US banking giant is acquiring a 65-person UK security consultancy, deepening its foothold in northern England and adding offensive security expertise to its in-house defences.

Key points
- Bank of America announced plans on Thursday to acquire MDSec Consulting Limited, a UK-based cybersecurity firm headquartered in Macclesfield, England.
- MDSec employs approximately 65 cybersecurity professionals and provides hands-on technical security consulting.
- The deal is expected to close in the fourth quarter of 2026, pending regulatory approvals.
- Financial terms were not disclosed.
Bank of America is buying MDSec Consulting Limited, a technical cybersecurity consultancy based in Macclesfield, England. The Charlotte, North Carolina bank announced the deal on Thursday. No price tag was made public.
MDSec does what's called offensive security: its staff break into clients' own systems, with permission, to find weaknesses before criminals do. That kind of hands-on penetration testing is in high demand from large financial institutions that need to know exactly how hard their defences are to crack. The firm has around 65 staff, small by corporate standards but tightly specialised.
Why does Bank of America want a small British firm?
Geography and expertise. Bank of America already employs more than 1,400 people in Chester, close to Macclesfield, and runs a cyber threat operations centre there. Adding MDSec to that cluster makes obvious sense.
MDSec co-founder Dominic Chell is well regarded in security research circles, and the firm's published work on red-teaming, simulating real attacker behaviour to stress-test defences, isn't the kind of capability a bank can build quickly from scratch. Our earlier story on Tal Kollander, the offensive-security practitioner who crossed to defence, is a useful frame for understanding why banks covet this profile.
Bank of America's chief information security officer, Kris Fador, said the bank had "long admired the exceptional ability of the MDSec team."
Chell framed it as a chance to scale. "Joining one of the world's leading financial institutions, one that reflects our culture of innovation and technical excellence, gives us an incredible opportunity to take that ambition to the next level," he told SecurityWeek.
Should you worry about MDSec's current clients?
That's the open question, and neither party addressed it in their announcement. MDSec has historically worked across industries, not just banking. Once it sits inside Bank of America, those relationships land inside a major competitor to some clients' own banks. Whether MDSec continues outside work or shifts entirely to internal projects is worth watching.
The deal still needs regulatory sign-off and won't complete until late 2026.
| Detail | Facts |
|---|---|
| Buyer | Bank of America (Charlotte, NC) |
| Target | MDSec Consulting Limited (Macclesfield, England) |
| MDSec staff | Approximately 65 |
| Deal value | Not disclosed |
| Expected close | Q4 2026 |
| Condition | Regulatory approvals required |
First reported by SecurityWeek, this deal fits a pattern: large banks are treating security talent as a strategic asset to own rather than contract. The Okta-Permiso acquisition we covered on 30 July made a similar bet, pulling specialist capability in-house rather than leasing it. The difference here is that a regulated bank now controls a team whose value to the broader market depended partly on its independence.



