>samit_hota
Back to security news
SN-2026-248InformationalResolved

Bank of America to Acquire UK Cybersecurity Firm MDSec

Samit Hota·
CVE ID
N/A
Affected Products / Orgs
Bank of America, MDSec Consulting
#news#vulnerability-disclosure#bank

In a notable shift toward internalizing high-end offensive security capabilities, Bank of America announced plans to acquire UK-based information security consultancy MDSec Consulting Limited. The Bank of America MDSec acquisition will bring roughly 65 specialized cybersecurity professionals into the financial institution’s internal defense and adversary simulation teams.

Details of the Bank of America MDSec Acquisition

The transaction is expected to close during the fourth quarter of 2026, pending standard regulatory approvals. Financial terms of the deal were not publicly disclosed.

Headquartered in Macclesfield, England, MDSec provides specialized technical security consulting, red teaming, and vulnerability research. The acquisition significantly expands the footprint of Charlotte, North Carolina-based Bank of America in northern England, where it already maintains a substantial presence. The bank currently employs more than 1,400 people in nearby Chester, operating a dedicated cyber threat operations center that monitors and defends its global infrastructure.

Commenting on the acquisition, Bank of America Chief Information Security Officer Kris Fador highlighted the consultancy’s reputation, noting that the bank has long admired the MDSec team’s capabilities and looks forward to bringing their work directly to the bank and its clients. MDSec co-founder Dominic Chell added that joining Bank of America will allow the firm to scale its technical innovation and research efforts within one of the world’s largest financial institutions.

Bringing Elite Offensive Capability In-House

For major financial institutions, managing systemic operational risk requires far more than basic compliance and commercial off-the-shelf defense tools. Sophisticated cybercrime groups and state-sponsored threat actors routinely target tier-one banks using custom tooling, complex living-off-the-land techniques, and multi-stage social engineering.

To defend against high-tier adversaries, financial institutions rely heavily on continuous red teaming, purple teaming, and proactive threat research—simulating the exact tactics, techniques, and procedures (TTPs) used by advanced threat actors. Historically, banks have balanced internal security teams with external security consultancies to conduct independent penetration tests and tradecraft development.

By absorbing a recognized consultancy like MDSec directly into its security organization, Bank of America secures direct control over specialized offensive skill sets, tradecraft, and research pipelines. Internalizing these functions allows the bank to conduct deep-dive security assessments across complex banking software, internal infrastructure, and cloud environments without the friction of short-term external contracting cycles.

What This Means for Financial Sector Cyber Operations

This move reflects a broader trend among major global enterprises seeking to mitigate technical risk by institutionalizing top-tier talent. While commercial managed detection and response (MDR) services cater to baseline enterprise needs, systemically important financial institutions often find that off-the-shelf security assessments lack the depth needed to evaluate custom financial networks and proprietary platforms.

By integrating MDSec’s staff into its Chester cyber threat operations center, Bank of America tightly bridges the gap between offensive vulnerability discovery and defensive engineering. For the broader cybersecurity market, acquisitions of this nature continue to concentrate elite technical talent within major enterprise targets, raising the bar for internal adversary simulation while reducing the availability of independent boutique consulting firms for the wider commercial market.

Found something similar in your stack?

Let's find out before it becomes an incident.

Book an advisory call