Key Takeaways
- Bank of America has announced plans to acquire MDSec Consulting Limited, a UK information security consultancy, to bolster its cyber defences, Reuters reported.
- MDSec, headquartered in Macclesfield, England, employs roughly 65 cybersecurity professionals specialising in technical penetration testing and threat research.
- The deal builds on Bank of America’s existing footprint in the North of England, where it already employs over 1,400 staff in nearby Chester.
- The transaction is expected to close in the fourth quarter of 2026, subject to regulatory approvals, with terms undisclosed, according to Yahoo Finance.
Bank of America has agreed to acquire MDSec Consulting Limited, a UK-based information security consultancy, as it looks to sharpen its cyber defences amid escalating digital threats to the financial sector.
The Charlotte-headquartered bank confirmed the deal would bring MDSec’s roughly 65 cybersecurity specialists in-house, expanding its established technology presence in the North of England.
Bank of America said the move reflects its push to deepen proprietary security capabilities rather than relying solely on external vendors, with the transaction expected to complete later this year.
What MDSec Brings to Bank of America
Founded in Macclesfield, Cheshire, MDSec has built its reputation on deeply technical information security consultancy, including penetration testing, red teaming and threat research for major organisations.
Bank of America’s own announcement said the acquisition would add specialist talent to its global cybersecurity organisation as cyber risk remains a strategic priority across financial services.
Kris Fador, the bank’s chief information security officer, said the firm had long admired MDSec’s capabilities and welcomed the chance for clients to benefit further from its work.
MDSec co-founder Dominic Chell said joining a major financial institution known for innovation offered the team a chance to extend its ambitions.
Deepening Roots in the North of England
The acquisition reinforces Bank of America’s substantial presence in the region, where it employs more than 1,400 people in nearby Chester, home to one of its global cyber threat operations centres.
Reuters notes the deal is expected to close in the fourth quarter of 2026 pending regulatory approvals, with financial terms not disclosed.
The move reflects a broader trend of financial firms bringing specialist expertise in-house rather than relying on external contractors for sensitive cybersecurity work.
It also lands as UK regulators sharpen scrutiny of major corporate takeovers more broadly, visible in the CMA probe into eBay’s acquisition of Depop, though this deal has drawn no such objections so far.
Part of a Wider Push on Cyber Resilience
The MDSec deal comes as cybersecurity moves higher on the agenda for UK organisations handling sensitive data, a debate also reflected in recent calls for tech firms to scan devices for child safety.
For Bank of America, bringing MDSec’s red teaming expertise in-house means testing its own systems more rigorously instead of relying on outside consultants.
Neither company has disclosed what MDSec’s leadership will be paid or how its existing clients will be handled after the deal closes.
For now, the acquisition signals that major banks now see specialist cybersecurity talent as something to own, not simply outsource.
Source: Bank of America to Acquire Information Security Consultancy M D Sec

